Understanding Sysmon & Threat Hunting with A Cybersecurity Specialist & Incident Detection Engineer

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 พ.ย. 2024

ความคิดเห็น • 18

  • @blindside995
    @blindside995 9 หลายเดือนก่อน +3

    Thanks, Tom and Amanda! This was super useful and informative!

  • @edlippjr
    @edlippjr 9 หลายเดือนก่อน +4

    super interesting stuff guys! thanks!

  • @jeep_in_mb
    @jeep_in_mb 9 หลายเดือนก่อน +3

    Thanks Tom and Amanda for that Interesting Presentation. Great Info. Brought back memories of Sleepless nights from my previous Job Posting as a lone System Administrator in a private medical clinic in Canada. It was a constant (losing) battle with the users (Doctors) to improve security. Thankfully those scary days are years behind me now.
    Any upcoming video to transfer sysmon logs into Graylog?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  9 หลายเดือนก่อน +1

      As I said in the video, I have a video on how to do that linked in the description th-cam.com/video/a3LbQow7i4Q/w-d-xo.html

  • @davidanderson2436
    @davidanderson2436 9 หลายเดือนก่อน +4

    How nice would it be if Microsoft included these utilities in a default install rather than the crap I have to spend an hour uninstalling! Great video thanks!

    • @collusion-d4n
      @collusion-d4n 9 หลายเดือนก่อน +1

      Most companies do not have storage requirements, system requirements etc to run sysmon by default this stuff would require planning, infrastructure etc. It would also require some sort of siem fowarder setup to ingest all that data recorded back into the siem. In other words, by default it would cause to much trouble. Corporate networks have all sorts of old tech, old OS's and legacy shit that shouldn't be there, but are bc well, they unfortunately need to be.

    • @davidanderson2436
      @davidanderson2436 9 หลายเดือนก่อน +2

      @@collusion-d4n Couldn't agree more - point was that a professional version of windows should have more utilities like these installed (by default - not necessarily running or configured - but at least available) rather than SnapChat, GameBox, Facebook, ChimClip, Spotify, Latest Office version - or whatever MS wants to shove down users throats at the time of install - they should save that for the Home version or not install it at all.

  • @L9INO9166
    @L9INO9166 8 หลายเดือนก่อน

    This is great. Made me want to check if Blumira is hiring.

  • @GordonSquared
    @GordonSquared 4 หลายเดือนก่อน

    Blumira is not available in my country and I'm extremely sad about it, because it looks great

  • @arronjablonowski7753
    @arronjablonowski7753 5 หลายเดือนก่อน

    Awesome talk! Thanks for the information. I would love to see a similar talk on Unix system security logging. Maybe even Sysmon for Linux.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  5 หลายเดือนก่อน

      Sysmon is needed for Windows because it does not have a good logging export system without it. Linux already has syslog and rsyslog to export to another server.

  • @kasta851984
    @kasta851984 7 หลายเดือนก่อน

    Great content, Thanks.
    Is it beneficial to implement Sysmon in conjunction with CrowdStrike EDR?
    What benefits does Sysmon provide that CrowdStrike doesn't?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  7 หลายเดือนก่อน

      I don't get the question. Sysmon is for logging and Crowdstrike is an EDR.

    • @kasta851984
      @kasta851984 7 หลายเดือนก่อน

      @@LAWRENCESYSTEMS Thank you for your reply. My question is: Is it worthwhile to implement Sysmon if we are already using Crowdstrike? I believe that Crowdstrike monitors everything that Sysmon does?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  7 หลายเดือนก่อน +1

      @@kasta851984 I don't use Crowdstike so I don't know

  • @ravisankar5297
    @ravisankar5297 7 หลายเดือนก่อน

    Really Helpful, Cheers...

  • @mmobini1803
    @mmobini1803 8 หลายเดือนก่อน

    Thank you!