Qradar SIEM - how to detect and mitigate attacks. Part 1

Поделиться
HTML-код
  • Опубликовано: 16 сен 2024

Комментарии • 7

  • @InfoSecGSO
    @InfoSecGSO 4 года назад +1

    That flow chart?? And demo?? Not too sure about that.. And here's why:
    You need a FireWall PFsense, an Enterprise managed switch, (maybe 2), and multiple devices logging events. Then, the logged events go into a centralized log aggregator. After which you place full PCAP taps on each network segment. Those will then be pushed to the centralized log aggregator. After that, the SIEM and Case management will pull from centralized logging. Lastly, you must be able to aggregate and correlate accross an Enterprise. To demonstrate this in a virtualized enviroment the guy needs to set up multiple DCs, Security Onion and about a dozen client VMs...That's just my 2 cents.

  • @DEDEPLDEDE
    @DEDEPLDEDE 2 года назад

    HD jakosc Panie Andrzeju by sie sprzydala

  • @albertpatel3344
    @albertpatel3344 4 года назад

    How he know the password while creating new user??? Answer pls

    • @InfoSecGSO
      @InfoSecGSO 4 года назад

      Maybe a default password? I don't know,. I stopped watching the vid after the flow chart.

    • @lithys29
      @lithys29 4 года назад

      27:30 : The system asks to set a password (and not enter an already defined one) for this new created user

  • @irshadakhter6613
    @irshadakhter6613 5 лет назад

    video quality is so bad..... i cant see the screen... its blur...

  • @xamo8687
    @xamo8687 3 года назад

    Like si veniste a jalartela.