Implementing MITRE ATT&CK into a SOC

Поделиться
HTML-код
  • Опубликовано: 6 фев 2025

Комментарии • 8

  • @JP-wd1yo
    @JP-wd1yo 3 года назад +4

    8:56 I like how there is a green screen of chicken wings behind you and nobody questions it in the comment section

  • @alexanderbrill1
    @alexanderbrill1 3 года назад +1

    Do you have the XML for that dashboard you made?

  • @洪培瑜-i4h
    @洪培瑜-i4h 3 года назад

    Hi can you help me??

  • @youbecks5647
    @youbecks5647 4 года назад

    Splunk is not a SIEM it is Big data tool.

    • @amyheng4892
      @amyheng4892 4 года назад +6

      Splunk enterprise security is a SIEM, built on a data platform.

    • @christopherharazinski5644
      @christopherharazinski5644 4 года назад

      @@amyheng4892 you are largely correct, but that depends of your definition of the SIEM. Enterprise Security (ES) has got extensions towards Threat Intel, UBA, automation, an incident response which makes the platform more valuable in comparicement to the traditional Gartner-definition of SIEM-products. Imagine best security practices in a box productized in form of interactive dashboards with several frameworks - that's your ES.