Using Defender for Endpoint for Deep Ransomware Investigation

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ก.ค. 2024
  • Take a look at how you can use Defender for Endpoint when performing deep investigation for Ransomware and other threats.
    In this demo, you will see how to investigate and remediate threats using the following capabilities:
    1 - Automated Investigation
    2 - Deep analysis
    3 - Adding files to indicators
    4 - Device Isolation
    5 - App restriction
    6 - Live response
    7 - Advanced hunting
    Please consider subscribing to my channel for the latest videos.
    I hope you enjoy and thanks for watching
    Jackson Felden

ความคิดเห็น • 5

  • @indiramourya2406
    @indiramourya2406 2 ปีที่แล้ว +2

    Excellent video. Thank you for uploading.

  • @tandasherman1360
    @tandasherman1360 6 หลายเดือนก่อน

    Awesome video!!

  • @kashifhasnain5458
    @kashifhasnain5458 ปีที่แล้ว +1

    Well explained on investigation.. keep up the good work

  • @GregThomson
    @GregThomson 2 ปีที่แล้ว +1

    Excellent video. Nice hands on actionable learning.

  • @RichardGailey
    @RichardGailey 2 ปีที่แล้ว +2

    That was one of the best deep dives in to what to do and how to react to certain alerts raised in Defender.
    Really liked the way that you did this.
    Regarding the IP addresses that were found in the Deep Analysis results; would these be good examples of addresses that you could create a KQL query for to add these IP's as IOC's for future events for all machines in the environment.
    Will you be doing a video n creating KQL queries in Azure and Defender (as the syntax differs) and most importantly, how to create an alert for the SOC team should any value be found in an query that you have created.
    One of the main issues that I am having at the moment, is trying to create alerts from queries that I have found online and also trying to figure out how to get an action to run when an alert is triggered, like Isolate the device instantly of a severe issue is found at 03:00hrs and we don't have a 24hr SOC.
    Liked and subbed. Awesome video.