Raph - SYSMON + ATT&CK to feed your SIEM
HTML-код
- Опубликовано: 10 фев 2025
- Endpoints are still a thing even though everyone has their heads in the clouds. There are many ways to deploy Sysmon to endpoints and get the logs that matter to enrich a story even when the EDR's fails. We will walk through an easy way to deploy and manage a Sysmon stack which uses Mitre as detections.
Bio: "In IT for 20+ years, Cyber for the last 5 or 6, I do threat detection engineering!"