- 40
- 17 449
Frankie Li
เข้าร่วมเมื่อ 3 ก.ย. 2017
วีดีโอ
Proactive Threat Hunting with ATTACK
มุมมอง 472 หลายเดือนก่อน
Proactive Threat Hunting with ATTACK - Cantonese
Emulation Lab Win10 Threat Hunting Demo
มุมมอง 1512 หลายเดือนก่อน
Emulation Lab Win10 Threat Hunting Demo
Demo of Using: WinDbg - EPROCESS and Procmon - Notepad
มุมมอง 147ปีที่แล้ว
You can download the result of this demo at: www.dropbox.com/scl/fi/q8pxjzma9d6kiuh1n9ccv/EPROCESS_Procmon_Notepad.zip?rlkey=bmvuvkg45othacjtzn11lw2ue&dl=0
crackle demo with intro IDA Pro and OllyDbg
มุมมอง 212ปีที่แล้ว
Crackme demo with intro IDA Pro and OllyDbg
BinText SectionTable (aka PE file format live demo)
มุมมอง 130ปีที่แล้ว
Demo to editing the virtual size on section table (.data) of BinText to find if the edited result affecting the effective execution of the (edited) BinText.
WinDbg Windows Internals (English)
มุมมอง 405ปีที่แล้ว
WinDbg Windows Internals (English) - For HKU COMP7905A
Azure Sentinel Walk-Through and ATT&CK-base Use Cases Live Demo
มุมมอง 1.5K3 ปีที่แล้ว
Azure Sentinel Walk-Through and ATT&CK-base Use Cases Live Demo
Part 1: SOC with Sentinel (My boring SOC comments, should skip and watch Part 2 directly)
มุมมอง 853 ปีที่แล้ว
Part 1: SOC with Sentinel (My boring SOC comments, should skip and watch Part 2 directly)
Covering Microsoft 365 Security Analytics with Sentinel vs Splunk (Part II)
มุมมอง 1723 ปีที่แล้ว
Covering Microsoft 365 Security Analytics with Sentinel vs Splunk (Part II)
Covering Microsoft 365 Security Analytics with Sentinel vs Splunk
มุมมอง 3043 ปีที่แล้ว
Covering Microsoft 365 Security Analytics with Sentinel vs Splunk
Memory Forensics Part II (Cantonese for Hong Kong)
มุมมอง 943 ปีที่แล้ว
Memory Forensics Part II (Cantonese for Hong Kong)
Memory Forensics Part I (Cantonese for Hong Kong)
มุมมอง 1463 ปีที่แล้ว
Memory Forensics Part I (Cantonese for Hong Kong)
Threat Hunting with Yara (in Cantonese for Hong Kong)
มุมมอง 983 ปีที่แล้ว
Threat Hunting with Yara (in Cantonese for Hong Kong)
thanks
How did you Configure the D:/Logs error? I would like to use C:\fuzzbunch\windows\Logs Should i change this in fuzzbunch? And where is the DSZOpsDisk.zip?
how to add these can i know please? thansk!
Why on earth would you want the overkill splunk for this, when there's a thing called ntopng ???
You should use a hexadecimal editor to your liking, and you can always use tools as additional to your findings. -Perform a static analysis and know the correct architecture and type of file extension. - If the program is packaged, indicate the compressor name and estimated version, if it is not, indicate section names - Determine if the file has anomalous characteristics in section, and indicate which ones, if any. - What is the value of the current checksum of the file (CheckSUM) - Calculate the offset (address) of the import table (IAT). - Extract the list of API functions present in the IAT of the executable (all), then explain using MSDN, at least what "one" of these APIs is for - Determine the size of the executable/binary, Without Overlay (without additional data), indicating the size in KB
Hi, I need help with this?
great video, thanks for the support!
Any guideline to install this dasboard sir?
it's a secret....
Hello Frankie, The files you have shared are all deleted. Can you please reshare it
your shared link item has been deleted. please reshare
11 Strategies of a World-Class Cybersecurity Operations Center | The MITRE Corporation
Thank you for the sharing
www.dropbox.com/s/d2i2eht08h8pevy/memory-forensics-part-1.pdf?dl=0 www.dropbox.com/s/5qsn2i8s1kq8y4b/Memory%20Forensics-Part%202.pdf?dl=0
Thanks for the video...
Please share the ppts
Thanks for the video...
Thanks for the video...
Thank you for the detailed analysis, it's very informative and valuable to those who are studying in this area.
I have added the installation instruction to the new dashboard. Can download here: www.dropbox.com/s/5572jva8p7n27hl/MISP%20and%20Splunk%20Dashboard%20Creation.pdf?dl=0
How u added misp in splunk ?? Please share Downloadable source ??
Thanks for the video...
Holà Frankie ! I've been searching for ways to integrate MISP intel to my Splunk and your plugin seemed a good lead. Are your dashboards included in the plugin ? if not do you mind disclosing them? Have a nice day !
can you send me an email to frankie@dragonadvancetech,com and give me a brief background of your work before I send you our Splunk app?