This was a cool demo I’m transitioning into cyber mainly soc analysis role I’ve heard about the elastic siem, I’m in the process of building a soc environment using the ELK stack
@emT__T2 жыл бұрын
Great demonstration of an entire IR scenario using Elastic Security. Thank you.
@udirt Жыл бұрын
Thanks for the video, there are a lot of workflow things you use I had never realized possible. Great to watch professional work! I don't know where to give you feedback, but one thing that is really a weakness at the moment is the out of the box baselining. seeing alerts on Linux for logrotate rotating logs of a common application, or on windows there's component hijacking alerts for adobe cloud, other alerts for ms defender doing its updates... It always makes your brain scream "are they even testing?". you need a larger lab running baselines and pre-tune those. do it for free as a quality measure or make a cheap subscription for that so you can have 100000s of people paying for it, totally fine, but bring it to a state that is "deliverable". Still watching, really really great content! Done, very, very much enjoyed it!
@jamesspiteri9478 Жыл бұрын
Hey @udirt, thanks for the feedback! Glad you enjoyed it. I do plan on releasing a v2 of this covering the new features that were added over the last year. Regarding feedback, I would encourage you to open an issue in our detections repo (which can be found in the description of the video). The team does test rules, and does their best to prevent false positives, but, as you know, there are always going to be situations were we wouldn't be able to test as extensively.
@sergeydrachuk86128 ай бұрын
Awesom!
@WatsonInfosec2 жыл бұрын
Thanks James love the work as always.
@muridin742 жыл бұрын
Can I know, what version of elasticsearch is used for this demo? I use 8.2.0, but there is no menu 'Detection & Respond'.
@seamusmalta2 жыл бұрын
This is 8.3.
@tonyhoang1818 Жыл бұрын
Nice demonstration, James! Are any of the features you used in this demonstration behind any paywalls?
@seamusmalta Жыл бұрын
Hi Tony, some of the features are indeed part of the commercial feature set.
@hiveontez5850 Жыл бұрын
does elastic IR have a built in dashboard for MTTD - MTTC?
@seamusmalta Жыл бұрын
Not yet.
@FTABoyNavid2 жыл бұрын
Could you share the other useful links for beginners?