Detecting User Login Anomalies with Shuffle - Building a Workflow to Detect Abnormal User Logins

Поделиться
HTML-код
  • Опубликовано: 22 окт 2024

Комментарии • 12

  • @fensterkiller3151
    @fensterkiller3151 2 года назад +1

    Thank you for your work!
    Btw what terminal client are you using?

  • @redhat3831
    @redhat3831 2 года назад

    thank you, great knowledge, but how can i interact with agent in cloud? or do you have link to that tutorial?

  • @MaliceDaModeler
    @MaliceDaModeler 2 года назад

    Thank you for the video! I am walking through it but my shuffle tool for the cache does not have the same values as the execution argument as yours does. I followed what you did but no dice. I am using on-prem as well. Did I miss something?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Malice, export your workflow and send me the json output either via email or discord and I will have a look. A workflow can be exported from the main workflow page.
      Thanks for watching :)

  • @norbsaw9501
    @norbsaw9501 2 года назад

    Thank you for your work!
    Mayby you can prepare video about integration OpenCTI with MISP, TheHive?

  • @mohamedkhamis-if3ki
    @mohamedkhamis-if3ki Год назад

    when another user login, it clear the last list created.
    Example: if an user: X login from specific country and then another user: Y logged in the cashed list of user: X will be replaced so if first user: X logged in again from deferent country shuffle will not detect him ?!! How can I solve this case?

  • @broph3n
    @broph3n 2 года назад +1

    Will you still use The Hive after it goes closed source?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +1

      Yes I still plan on using thehive, but that decision may change in the future..once I get my hands on thehive 5, I will be able to reach a better conclusion

  • @numanmaavia8575
    @numanmaavia8575 2 года назад

    Thanks

  • @moh_ryzki
    @moh_ryzki 2 года назад

    how to delete updated alert on thehive, i try ro remove that but i can't