Threat Hunting in Security Operation - SANS Threat Hunting Summit 2017

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 ก.พ. 2025

ความคิดเห็น • 13

  • @lancemarchetti8673
    @lancemarchetti8673 2 ปีที่แล้ว

    Thanks Chris, this was a great soc delivery 👍🏽

  • @CReesman
    @CReesman 7 ปีที่แล้ว +2

    Very informative video. My biggest takeaway was to take 1 hour a week to work on threat hunting at some level. Thanks!

  • @barryabrams6071
    @barryabrams6071 5 วันที่ผ่านมา

    How does an analyst perform threat hunting and detect attacks on edge devices such as routers, firewalls, F5, switches, etc.? How to detect adversaries "Living Off The Land" and taking advantage of edge devices? Is the approach to detecting attacks on edge devices specific to the SIEM (Ex: QRadar) and how to query the logs? If so, how do I find keywords to search, strings to search, Event IDs, etc.? Are the keywords, strings, and event IDs vendor specific to search and detect malicious behavior? So far, the only solutions I have found to detect attacks on edge devices are CVEs and Nessus Plugins. Any assistance would be much appreciated.

  • @RafaelOliveira-vg8gq
    @RafaelOliveira-vg8gq 5 ปีที่แล้ว +1

    Another amazing video, its help a lot.
    Thank you guys

  • @MrKensh
    @MrKensh 7 ปีที่แล้ว

    I really enjoyed this video... thank you!

  • @jonathanmoore6446
    @jonathanmoore6446 5 ปีที่แล้ว

    Thank you for this video. I plan on sharing with my team.

    • @darnellmac9981
      @darnellmac9981 5 ปีที่แล้ว

      Just looking to help companies save money. Another see something say something program. Is he suggesting to pay employees extra for scripts when they are not scripting but help desk.

  • @mploi9759
    @mploi9759 4 ปีที่แล้ว

    But he doesn't explain why the Easter bunny lays eggs @eastertime?

  • @moretwocome21
    @moretwocome21 6 ปีที่แล้ว

    The audio is extremely bad!!!

    • @MoSec9
      @MoSec9 6 ปีที่แล้ว +6

      Mor2come21 You must have watched another video. Otherwise, check your equipment. The audio is actually “extremely” good.

    • @CCrowMontance
      @CCrowMontance 5 ปีที่แล้ว

      Sorry. I didn't think the audio was so bad. Are there parts that you didn't understand that I can elaborate on?

    • @ejoviag6561
      @ejoviag6561 5 ปีที่แล้ว

      Chris Crowley hi Chris, please could you share the link to resource mentioned in the video. Will be great to go through it.
      Thanks

    • @CCrowMontance
      @CCrowMontance 5 ปีที่แล้ว +3

      @@ejoviag6561 - All my resources that are publicly available are here: www.mgt517.com/soc . Lots of slide decks and files to download!