Hack The Box SOC Analyst Lab - Unit42 (Sysmon)

Поделиться
HTML-код
  • Опубликовано: 17 ноя 2024

Комментарии • 34

  • @MustafaAhmedQasemYahya
    @MustafaAhmedQasemYahya 2 месяца назад

    You are anazing. Very nice. Thanks

    • @MyDFIR
      @MyDFIR  2 месяца назад

      Wow, thank you!

  • @RubenMuñozAragon-e9n
    @RubenMuñozAragon-e9n 4 месяца назад +1

    Great. Please I LOVE content of Splunk. Thanks.

    • @MyDFIR
      @MyDFIR  4 месяца назад +2

      More to come!

  • @SayoOlanbiwonnu
    @SayoOlanbiwonnu 4 месяца назад

    Amazing Delivery as usual ❤

    • @MyDFIR
      @MyDFIR  4 месяца назад

      Thank you ❤️

  • @MoSiraji
    @MoSiraji 4 месяца назад

    Thank you good for training

    • @MyDFIR
      @MyDFIR  4 месяца назад

      You’re welcome! Hope you had some fun and learned new things 👍

    • @MoSiraji
      @MoSiraji 3 месяца назад

      @@MyDFIR Yes, I did.

  • @irocz5150
    @irocz5150 4 месяца назад

    Excellent video. Sad to say but sysmon generates lots of logs and sometimes there is a push back installing this amazing tool.

    • @MyDFIR
      @MyDFIR  4 месяца назад

      You’re absolutely correct but there are some companies out there that have it!

  • @mapletech_22
    @mapletech_22 4 месяца назад

    Amazing work 👏 🙌 👌 ❤

    • @MyDFIR
      @MyDFIR  4 месяца назад +1

      Thank you 🙌

  • @aplik3
    @aplik3 4 месяца назад

    I was just planning to do this room today :D Great video!

    • @MyDFIR
      @MyDFIR  4 месяца назад +1

      Have fun!

  • @anitagd
    @anitagd 4 месяца назад

    Great video as usual 🔥

    • @MyDFIR
      @MyDFIR  4 месяца назад

      Appreciate it!

  • @thebodythehead
    @thebodythehead 4 месяца назад

    amazing video

    • @MyDFIR
      @MyDFIR  4 месяца назад

      Thanks!

  • @Abc-sl1nf
    @Abc-sl1nf 4 месяца назад

    Thx!

  • @Whiterqbbit
    @Whiterqbbit 4 месяца назад

    Fancy using Splunk, I would of probably used ZT Timeline Explorer - Going have to checkout that splunk video.

    • @MyDFIR
      @MyDFIR  4 месяца назад

      heheh thanks! I love sifting through logs using Splunk as I can better visualize the data but I'd recommend using any tool that does the job!

  • @erglaligzda2265
    @erglaligzda2265 3 месяца назад

    Any bright idea how to monitor end-point DNS queries? Now I am using sysmon, but not always it captures end-points IP and/or user. :(

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Strange, Sysmon Event ID 22 should capture the source IP of the endpoint and you can correlate that with other event IDs if required

    • @erglaligzda2265
      @erglaligzda2265 3 месяца назад

      @@MyDFIR I thought so too, but on-premise environment it may not happen. Thanks for pointing out Event ID. I'll take a second into config file. :)

  • @myles5253
    @myles5253 4 месяца назад

    Do you use a VM for Hackthebox labs?

    • @godwinalekeobor5274
      @godwinalekeobor5274 4 месяца назад

      You can use their VM, if you subscribe

    • @MyDFIR
      @MyDFIR  4 месяца назад

      Any labs I do, I always use a VM. That way I can revert it pretty easily if I need to.

  • @ItsCynik
    @ItsCynik 4 месяца назад

    wen next project? 😢

    • @MyDFIR
      @MyDFIR  4 месяца назад

      Heheh TBD! These take a long time to do. Have you completed all of the ones on my channel?

  • @mariostevenquijivix5752
    @mariostevenquijivix5752 3 месяца назад

    Im using a Mac. Is there another way aside from 7zip top extract the folder?

    • @MyDFIR
      @MyDFIR  3 месяца назад +1

      I believe Mac has a built in extractor where you could double click and should do the trick.

  • @imca_b_5517
    @imca_b_5517 4 месяца назад

    Brother please don't upload video of hack the box because it was not free and + we are students so we don't have enough money for that but if you make video on other Topics so I will help

    • @MyDFIR
      @MyDFIR  4 месяца назад +5

      But it is free or at least portions of it. All the labs I’ve uploaded so far are free that you can do and follow along. Unless I am missing something?