No video

End to End Incident Response Using Elastic Security

  Рет қаралды 17,940

Elastic

Elastic

Күн бұрын

Пікірлер: 14
@deanhaycox
@deanhaycox 11 сағат бұрын
This was a cool demo I’m transitioning into cyber mainly soc analysis role I’ve heard about the elastic siem, I’m in the process of building a soc environment using the ELK stack
@emT__T
@emT__T 2 жыл бұрын
Great demonstration of an entire IR scenario using Elastic Security. Thank you.
@udirt
@udirt Жыл бұрын
Thanks for the video, there are a lot of workflow things you use I had never realized possible. Great to watch professional work! I don't know where to give you feedback, but one thing that is really a weakness at the moment is the out of the box baselining. seeing alerts on Linux for logrotate rotating logs of a common application, or on windows there's component hijacking alerts for adobe cloud, other alerts for ms defender doing its updates... It always makes your brain scream "are they even testing?". you need a larger lab running baselines and pre-tune those. do it for free as a quality measure or make a cheap subscription for that so you can have 100000s of people paying for it, totally fine, but bring it to a state that is "deliverable". Still watching, really really great content! Done, very, very much enjoyed it!
@jamesspiteri9478
@jamesspiteri9478 Жыл бұрын
Hey @udirt, thanks for the feedback! Glad you enjoyed it. I do plan on releasing a v2 of this covering the new features that were added over the last year. Regarding feedback, I would encourage you to open an issue in our detections repo (which can be found in the description of the video). The team does test rules, and does their best to prevent false positives, but, as you know, there are always going to be situations were we wouldn't be able to test as extensively.
@sergeydrachuk8612
@sergeydrachuk8612 8 ай бұрын
Awesom!
@WatsonInfosec
@WatsonInfosec 2 жыл бұрын
Thanks James love the work as always.
@muridin74
@muridin74 2 жыл бұрын
Can I know, what version of elasticsearch is used for this demo? I use 8.2.0, but there is no menu 'Detection & Respond'.
@seamusmalta
@seamusmalta 2 жыл бұрын
This is 8.3.
@tonyhoang1818
@tonyhoang1818 Жыл бұрын
Nice demonstration, James! Are any of the features you used in this demonstration behind any paywalls?
@seamusmalta
@seamusmalta Жыл бұрын
Hi Tony, some of the features are indeed part of the commercial feature set.
@hiveontez5850
@hiveontez5850 Жыл бұрын
does elastic IR have a built in dashboard for MTTD - MTTC?
@seamusmalta
@seamusmalta Жыл бұрын
Not yet.
@FTABoyNavid
@FTABoyNavid 2 жыл бұрын
Could you share the other useful links for beginners?
@seamusmalta
@seamusmalta 2 жыл бұрын
They’re in the description.
Elastic Security | AI Assistant Demo
11:31
Elastic
Рет қаралды 1,4 М.
Limitless XDR with Elastic Security
55:19
Official Elastic Community
Рет қаралды 8 М.
Violet Beauregarde Doll🫐
00:58
PIRANKA
Рет қаралды 48 МЛН
PEDRO PEDRO INSIDEOUT
00:10
MOOMOO STUDIO [무무 스튜디오]
Рет қаралды 24 МЛН
This Dumbbell Is Impossible To Lift!
01:00
Stokes Twins
Рет қаралды 42 МЛН
Hunting for Suspicious HTTPS and TLS Connections
1:02:50
SANS Cyber Defense
Рет қаралды 4,3 М.
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 96 М.
How To Use The Elastic Stack as a SIEM - John Hubbard
1:14:17
John Hubbard
Рет қаралды 54 М.
What is Endpoint Detection and Response (EDR)?
5:34
IBM Technology
Рет қаралды 49 М.
CISSP 2024 exam changes in DETAIL!
1:40:42
Destination Certification
Рет қаралды 57 М.
Easier integrations with Elastic Agent & Fleet
22:43
Elastic
Рет қаралды 22 М.
Cybersecurity IDR: Incident Detection & Response | Google Cybersecurity Certificate
1:43:03
Violet Beauregarde Doll🫐
00:58
PIRANKA
Рет қаралды 48 МЛН