Raph - SYSMON + ATT&CK to feed your SIEM

Поделиться
HTML-код
  • Опубликовано: 10 фев 2025
  • Endpoints are still a thing even though everyone has their heads in the clouds. There are many ways to deploy Sysmon to endpoints and get the logs that matter to enrich a story even when the EDR's fails. We will walk through an easy way to deploy and manage a Sysmon stack which uses Mitre as detections.
    Bio: "In IT for 20+ years, Cyber for the last 5 or 6, I do threat detection engineering!"

Комментарии •