SOF ELK® A Free, Scalable Analysis Platform for Forensic, Incident Response, and Security Operation

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 พ.ย. 2024

ความคิดเห็น •

  • @sekarov
    @sekarov ปีที่แล้ว +1

    Do this SOFELK have parser to parse windows and Linux log fields. The provided ELK in FOR508 dosent have parser to parse windows logs, so I find very difficult to pivot the logs for investigation.

  • @francescofaenzi7095
    @francescofaenzi7095 3 ปีที่แล้ว

    Any experience integrating SOF-ELF with SIGMA rules?

  • @stelluspereira
    @stelluspereira 4 ปีที่แล้ว +1

    is there way to get the large set of logs downloadable from your web portal (which you mentioned that you have during the talk, size 500GB ?)

    • @fleetr06
      @fleetr06 4 ปีที่แล้ว

      Do you have them available to people? I have them already on 3 jump drives, but only because I went to the Bootcamp.

    • @stelluspereira
      @stelluspereira 4 ปีที่แล้ว

      Dear fleetr06 ,
      Is there a way to share(if it is ok with the trainer)

    • @fleetr06
      @fleetr06 4 ปีที่แล้ว

      @@stelluspereira I don't have a way to host them, but if I was you I would reach out to SANs. They are pretty cool.

    • @stelluspereira
      @stelluspereira 4 ปีที่แล้ว

      fleetr06 , Thankyou Sir
      I am not sure how to reach them

    • @stelluspereira
      @stelluspereira 4 ปีที่แล้ว

      @@fleetr06 , i can send you an usb drive, what would best way to contact you

  • @arsalananwar8265
    @arsalananwar8265 2 ปีที่แล้ว +1

    wow