Event Log Chainsaw Massacre - Powerful Threat Detection

Поделиться
HTML-код
  • Опубликовано: 30 июл 2024
  • In this episode, we'll look at Chainsaw - a powerful new tool that can help us parse Windows Event Logs. Chainsaw provides both searching and hunting capabilities, and even includes built-in detection rules to find anomalistic behavior and the ability to load Sigma rules for even more advanced detection.
    ** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **
    📖 Chapters
    00:00 - Intro
    01:26 - Chainsaw Searching
    09:27 - Chainsaw Hunting
    16:24 - Recap
    🛠 Resources
    #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
  • НаукаНаука

Комментарии • 23

  • @yannickleroy7419
    @yannickleroy7419 2 года назад +6

    Not sure why this was in my recommended, but it was actually quite interesting. Thank's for showcasing this, subbed!

  • @mallikab8707
    @mallikab8707 2 года назад +1

    Awesome 👌 Thank for your time and I will explore more on this.

  • @lonegunmen1985
    @lonegunmen1985 Год назад +1

    Awsome! Thanks for sharing the knowlege

  • @castle228
    @castle228 2 года назад +3

    Going to have to add this tool to the repertoire

  • @rogerioabreu3081
    @rogerioabreu3081 2 года назад +3

    awesome. thnx

  • @orlandop4sun
    @orlandop4sun 10 месяцев назад

    Great job on this video.. súper profesional

  • @samjohn1098
    @samjohn1098 2 года назад

    Pretty cool.. Nice

  • @adrianguerrero9583
    @adrianguerrero9583 2 года назад +2

    can you also do a preview/walkthrough for the Hayabusa tool by Yamato-Security.
    it looks like they are almost the same.

  • @NetworkITguy
    @NetworkITguy 2 года назад +3

    This with velociraptor is gg

    • @sulthansk6444
      @sulthansk6444 2 года назад

      @Lordyzagat velociraptor ir tool

  • @benw4529
    @benw4529 Год назад

    What happen to the syntax the commands to not work

  • @amirhosseinhemmati9290
    @amirhosseinhemmati9290 Месяц назад

    can you please provide a link to log database that you used

    • @13Cubed
      @13Cubed  Месяц назад

      Hi, unfortunately that test database has been long since removed.

  • @artember1200
    @artember1200 2 года назад

    does this require sysmon to be effective?

    • @13Cubed
      @13Cubed  2 года назад

      No, but Sysmon is certainly highly beneficial.

  • @otvs5838
    @otvs5838 2 года назад +1

    Please share the Latest and safest source link to download chainsaw .

    • @13Cubed
      @13Cubed  Год назад +1

      github.com/WithSecureLabs/chainsaw/releases

  • @Revoc
    @Revoc Год назад

    This seems to be out of date now with their update.

    • @13Cubed
      @13Cubed  Год назад

      Such is life with RUclips... will consider making an update at some point.

  • @ishannair1335
    @ishannair1335 5 месяцев назад

    none of these commands work for me. amazing

    • @13Cubed
      @13Cubed  5 месяцев назад

      What error do you receive when you try? I need a little more detail if you want to solve the issue.