Загрузка страницы

How To Use The Elastic Stack as a SIEM - John Hubbard

A talk I gave at the Philly Security Shell meetup 2019-02-21 on how the Elastic Stack works and how you can use it for indexing and searching security logs.

Tools I mentioned:
Github repo with script and demo data - https://github.com/SecHubb/SecShell_Demo
Cerebro - https://github.com/lmenezes/cerebro
Elastalert - https://github.com/Yelp/elastalert
===
For info on my SANS teaching schedule visit: https://www.sans.org/instructors/john-hubbard
Twitter: https://twitter.com/SecHubb
My SANS Courses:
- SEC450 - Blue Team Fundamentals: https://sans.org/sec450
- MGT551 - Building and Leading Security Operations Centers: https://sans.org/mgt551

Blueprint Podcast: https://sans.org/blueprint-podcast
Twitter: https://twitter.com/SecHubb

Видео How To Use The Elastic Stack as a SIEM - John Hubbard канала John Hubbard
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
22 февраля 2019 г. 18:24:13
01:14:17
Яндекс.Метрика