BHIS | Intro to Windows Event Collecting | Nick & Noah | 1 Hour

  Рет қаралды 5,864

Black Hills Information Security

Black Hills Information Security

Күн бұрын

Пікірлер: 9
@GabrielSanchez-rh6lv
@GabrielSanchez-rh6lv 2 жыл бұрын
Thank you for continuing to put out great security information. Taking your SOC skills course and loving it!
@computerguy79
@computerguy79 2 жыл бұрын
gnarly timing. I'm actually working on implementing this in my environment this week and this webcast helped fill in many gaps; especially the pitfalls pieces. Thanks guys.
@tylercoan
@tylercoan 2 жыл бұрын
Awesome stuff guys! Super informative and I can’t wait to get this going in my lab and hopefully get it going in production.
@safurniss
@safurniss Жыл бұрын
What about for collecting logs from non-domain joined servers... say those in your DMZ ?
@vincegremillion1533
@vincegremillion1533 2 жыл бұрын
Winlogbeats service on the WEC wont start, it seems to be looking for the CRT file that isn't there. I searched text in closed caption transcripts and no mention of how to create a cert or not reference a cert in the WLB config.
@rajashekarmeegada2127
@rajashekarmeegada2127 Жыл бұрын
Can we use a VIP in front of multiple WECs in a large environment to be able to forward logs from large no of workstations?
@BlackHillsInformationSecurity
@BlackHillsInformationSecurity Жыл бұрын
Tthat's really hard to say without more dialog. winrm can handle using proxy servers and could probably be load balanced without breaking certificate chains. we have recommended for larger environments with multiple sites to use multiple Windows Event Forwarding policies with each policy specifying different WECs and applied to different Active Directory OUs as appropriate for the environment. all that said... i'm like 99% sure you can specify more than 1 WEC in the WEF policy so if you're are talking large number of systems all at the same site and same OUs maybe the easiest thing is to just specify multiple WECs on the policy - Nick Caswell
@matthewkerr3972
@matthewkerr3972 2 жыл бұрын
I am working through this right now, ran into some issues with the enablewinrm on DC. Is there a spot in the BHIS discord server where I can bounce questions off of others that are setting this up?
@matthewkerr3972
@matthewkerr3972 2 жыл бұрын
Nevermind, I think I figured it out. I need to go through each Defcon. I thought you could stop at 4 to get this all done. You guys Are heroes.
BHIS | Atomic Red Team Hands on Getting Started Guide | Carrie & Darin Roberts | 1 Hour
1:10:05
Black Hills Information Security
Рет қаралды 12 М.
BHIS | How DNS can be abused for Command & Control | Troy Wojewoda | 1 Hour
1:02:44
Black Hills Information Security
Рет қаралды 4 М.
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 259 МЛН
Turn Off the Vacum And Sit Back and Laugh 🤣
00:34
SKITSFUL
Рет қаралды 9 МЛН
BHIS | Offensive Windows Event Logs | Tim Fowler | 1 Hour
1:09:55
Black Hills Information Security
Рет қаралды 4,2 М.
The SOC Age  Or, A Young SOC Analyst's Illustrated Primer | John Strand | 1 Hour
1:17:58
Black Hills Information Security
Рет қаралды 24 М.
Step-by-Step Guide: Sending Windows Event Logs to Graylog With NXLOG
10:12
How to Build your Own Cybersecurity Lab? Practice cyber at home!
58:54
BHIS | Uncovering Secrets and Simplifying Your Life with CyberChef - BB King
50:29
Black Hills Information Security
Рет қаралды 6 М.
Think You're Compromised?  What Do We Do Next?
1:02:27
Black Hills Information Security
Рет қаралды 7 М.
Event Log Chainsaw Massacre - Powerful Threat Detection
18:48
Threat Hunting via Sysmon - SANS Blue Team Summit
51:01
SANS Institute
Рет қаралды 63 М.
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
Windows Event Forwarding at Scale
33:02
H & A Security Solutions
Рет қаралды 17 М.
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 259 МЛН