As a new soc analyst, I found this video very valuable! I got so much insight in such a short amount of time as well as how you should investigate and look into activities. Thanks a ton!
@rmcgraw79432 жыл бұрын
Been an Ent Architect for 25+ yrs and that’s the best clearest, most concise explanation of determining how best to find hidden processes on computers. Thanks.
@KeatronEvans2 жыл бұрын
Thank you for watching!
@laureanocavallo24763 жыл бұрын
I felt this 12 minutes like 5 minutes. That's when you can tell it's a good video. Entertaining, informative and educational.
This is great. It is rare to find such a good walkthrough on this stuff. Thanks!
@x0rZ15t3 жыл бұрын
Finally, a real look into the trenches of SOC and IR. Please keep up a good work!
@KeatronEvans2 жыл бұрын
Thank you for watching!
@johnpiernicky86742 жыл бұрын
I'm trying to get a job as a SOC Analyst Tier 1. I was told that Exabeam was used in addition to Splunk. I am grateful for these videos as they really give a good demonstration and let the viewer see how this works. The dashboard looks great and user friendly, and the ability to move from the dashboard to investigating the alert is a nice thing to see.
@draperw86 Жыл бұрын
Dang Keatron you break it down like this was a sermon !! This is awesome
@FracturesHD3 жыл бұрын
This was an amazing video! I recently got a job as a IR team member after a few years of being a network analyst. Although I have the foundations, I am very new to the job itself so this type of video helps me so much! I will definitely be subscribing!
@wilfredoperez18043 жыл бұрын
How long have you been doing IT? Do you recommend any certs?
@ExabeamSIEM3 жыл бұрын
We're so glad you found it useful!
@FracturesHD3 жыл бұрын
@@wilfredoperez1804 I've been in the field about 10 years total now if you include education. I currently only have my CompTIA Sec+ and Net+ but for some reason HR departments love those. I don't think they're worth all that much personally, but the amount of offers I got after getting my Sec+ was crazy. I also would recommend looking into the GIAC certifications if you are getting serious about this sort of stuff! I hope you are able to make it into the field easily!
@gopim61423 жыл бұрын
Could you please give me your contact number, am also trying to soc analyst
@daslynhug8953 Жыл бұрын
Whew would recommend this video to anyone! Thank you for a value add!
@nicksmith54003 жыл бұрын
Why does this only have 1.5k views? Great walkthrough sir.
@ExabeamSIEM3 жыл бұрын
Trending upward!
@okeyokafor6483 жыл бұрын
It has 20k views now.
@kharikyle36103 жыл бұрын
Sorry to be so offtopic but does anyone know of a tool to log back into an instagram account..? I stupidly forgot my password. I appreciate any help you can give me.
@nasirkyng67663 жыл бұрын
@Khari Kyle Instablaster =)
@kharikyle36103 жыл бұрын
@Nasir Kyng thanks so much for your reply. I got to the site thru google and Im in the hacking process now. Seems to take quite some time so I will reply here later with my results.
@WilliamSalisbury3 жыл бұрын
Exactly the kind of content I needed!! Thanks a billion
@KeatronEvans2 жыл бұрын
Thank you for watching!
@brianphamtv6916 Жыл бұрын
This is the content I’m looking for earned subscriber 🎉
@jackchn2311 ай бұрын
Thanks Keatron! Subbed to YOUR channel!
@KishorKumar-z8e3 ай бұрын
thanks a lot for valuable video please keep doing such a videos very informative. thanks again.
@xCheddarB0b42x Жыл бұрын
This was excellent: short, informative, and clear. Thank you!
@tinatwintinny12059 ай бұрын
Thank you for sharing. I have been trying to get an entry-level job as a SOC, and 😐it's an exciting role.
@miloboy55 Жыл бұрын
I’m only 4:18 in and I must say this is an excellent video.
@threadripper37502 жыл бұрын
A+ material. i will be ready for my upcoming table top exercise. Thanks a bundle!
@KeatronEvans2 жыл бұрын
Thank you!
@dgmckenzie113 жыл бұрын
Good content! I look forward to part 2.
@mml12243 жыл бұрын
great job, esp.2prep 4 interviews this was handy, keep it comin, youll get 1m subs
@jordanbourcier24242 жыл бұрын
Great video!!
@KeatronEvans2 жыл бұрын
Thanks!
@Foxy10-b6n3 жыл бұрын
just getting in and this was fun to watch
@KeatronEvans2 жыл бұрын
Thank you!
@KeatronEvans2 жыл бұрын
Thanks for watching!
@RichfieldFearless2 жыл бұрын
This was very educative .
@KeatronEvans2 жыл бұрын
Thank you!
@libnatty18622 жыл бұрын
Thanks for the great behind the scenes look into SIEM monitoring. It's sad that I have a degree from a technical college, and there were hardly any labs, just all theory. I naturally have an investigative mindset so this really intrigues me and I would love to get back into training. Keatron, where does one start?
@_amintrouble2 жыл бұрын
Hi, thanks for the video. Although you mentioned it, using the md5 command is a lot better and quicker as it gives you the instant hash which you can copy and paste into VT.
@KeatronEvans2 жыл бұрын
Thank you!
@brittb77663 жыл бұрын
This was an awesome video
@KeatronEvans3 жыл бұрын
Thank you!
@KeatronEvans2 жыл бұрын
Thank you
@MrBitviper2 жыл бұрын
awesome video. thanks for the detailed explanation
@KeatronEvans2 жыл бұрын
Thank you for watching!
@natashataylor75312 жыл бұрын
Great video! Thank you!
@KeatronEvans2 жыл бұрын
Thank you!
@rrw19813 жыл бұрын
Great video
@cecilkimaro14862 жыл бұрын
It’s a good video. Thank you for giving us a light on this matter.
@KeatronEvans2 жыл бұрын
Thank you for watching!
@cedricroberts43363 жыл бұрын
Thank you so much for this insightful video.
@KeatronEvans2 жыл бұрын
Thank you for watching!
@marcschweiz3 жыл бұрын
Absolutely fantastic info
@KeatronEvans2 жыл бұрын
Thank you!
@shafiiqbal6312 жыл бұрын
what should be the design or architecture of a SOC Center? Please provide and assist my new SOC Center.
@Jo-nw2lf2 жыл бұрын
Great video but i tried to download the exabeam but cant. do i have to pay for full download?
@zacherymahoney12 Жыл бұрын
Just super cool. This is why its so fun
@TrackMonkey3273 жыл бұрын
That was a great video. I learned a lot. Thank you so much for posting this.
@KeatronEvans2 жыл бұрын
Thank you!
@amechi2 жыл бұрын
Excellent 👍🏾
@Whatthellisthisthing3 жыл бұрын
Great demonstration, thank you!
@KeatronEvans2 жыл бұрын
Thank you!
@laanbarehamza10242 жыл бұрын
Amazing video. Thanks so much
@KeatronEvans2 жыл бұрын
Thank you for watching!
@emmanueleniade75582 жыл бұрын
Please I have a question. Is security+ course okay for new Comer into cyber security
@EdwardAmarh-012 жыл бұрын
Wow this was so informative. I really needed it, same question bothered me, how do you know when to dig deeper into an alert. Thanks
@KeatronEvans2 жыл бұрын
Thank you!
@msudex3 жыл бұрын
Hello. Why we did not see that connections/processes on a victim's machine? Was the rootkit hiding that and only having a dump outside of the victims' machine made the rootkit not interfere the proper outcome of connection/processes?
@KeatronEvans2 жыл бұрын
Yes, the rootkit was not allowing Windows to "show" you the connections.
@manfrombritain68163 жыл бұрын
great video!
@KeatronEvans2 жыл бұрын
Thanks!
@renelvital Жыл бұрын
Thank you for the video.
@dutchhome12123 жыл бұрын
Great vid m8! If I may make 2 suggestions (you might already know...): if you first do the RAM memdump be4 using netstat and so on, you wont throw something out of the RAM because you just used two programs. Second, you can also upload a hash of the rootkit to VirusTotal and not the file itself, so not to alert anyone... All in all a great and informative video! Keep up the good work!
@KeatronEvans2 жыл бұрын
Doing a memdump required putting something external on the machine, running netstat did not. The memory dump is far more disruptive than running netstat which is local. Thanks for watching!
@ekomeebahcollins43402 жыл бұрын
Really great. I appreciate honestly
@KeatronEvans2 жыл бұрын
Thank you!
@lilmamagc2 жыл бұрын
Wow this was so helpful
@juliusweston80369 ай бұрын
Awesome Stuff!
@TenMinuteKQL3 жыл бұрын
You have an alert suggesting there may be an issue, but it was not clear that something was definitively wrong. This is the investigative process for the INV team. Once you know it is a true positive and worthy of time for containment and analysis by a dedicated team (impact to organization) it is then transferred to IR. At least in my experience. This is a good rundown of a tier 2 INV investigation.
@emreybs25632 жыл бұрын
Thanks. Very useful.
@KeatronEvans2 жыл бұрын
Thank you!
@ishwaryanarayan1010 Жыл бұрын
Sir your videos are great . I am looking for trial version to update my skills . Do you offer free trial version?
@akotamaki3385 Жыл бұрын
Great video thank you
@raveollorza18772 жыл бұрын
ITS REALLY WORKED LOL THANK YOU DUDE
@mannym8ker3 жыл бұрын
really useful, thanks bro
@KeatronEvans2 жыл бұрын
Thank you!
@kevincastillo92073 жыл бұрын
I wasn't aware Victor Wooten was into cyber security!
@KeatronEvans3 жыл бұрын
Awesome comment! I've been playing since I was a kid.
@BarCast101 Жыл бұрын
this is a good staff, How to do it on kubernetes?
@PaulEllisBIGDATA3 жыл бұрын
Outstanding!!!!
@KeatronEvans2 жыл бұрын
You're outstanding! Thank you!
@Ultimah3 жыл бұрын
fanstatic video please make more video tutorials.
@KeatronEvans2 жыл бұрын
Will do, thanks!
@zak1686 Жыл бұрын
Thank you %100 works
@MohammadAliKhalil2 жыл бұрын
This looks difficult to do all of these steps, what type of position do this type of work
@KeatronEvans2 жыл бұрын
It's not difficult, just takes practice.
@vivekprajapati47873 жыл бұрын
Is RSA security analytics siem tool good?
@toliskoutovas7267 Жыл бұрын
Trying to get into SOC T1. What if instead of uploading the rootkit executable on VirusTotal, you instead extracted its hash and compared it to the virustotal database? Wouldn't that be safer?
@kevinmcguinness6526 Жыл бұрын
Thanks man
@ABDULBASIT-q8m7f4 ай бұрын
what is the software used @ 7.50 ?
@BrookeThePersonalTrainerАй бұрын
thank you!
@Mustafa-bd3db3 жыл бұрын
Is this open source? I would like to practice
@jksalamon Жыл бұрын
Wanted to check on SOC. Can there be an IT SOC and an OT SOC. Is it right to say so. Or is it just one SOC and have a SIEM separately for IT and OT. In one of our groups we had this endless debate about SOC, each side backed with their own experience and opinions. What do you think is the right approach, any document/whitepaper you can share that you know of.
@cipher40473 жыл бұрын
Hi, if you don't use virustotal to identify malware, what commercial tool do you use? Also, please make more videos. I will support the channel!
@Ray-p8d5 ай бұрын
How to resolve this one?
@mohittyagi26912 жыл бұрын
dude tNice tutorials is super good! subbed
@jeffnaval489410 ай бұрын
It looks simple. not too much coding. Finally i have a dreamjob i'm dreaming about.
@gradseven79962 жыл бұрын
Can you make more videos like this please
@emmanuelanosike22082 жыл бұрын
GENIUS
@prachivirkud72862 жыл бұрын
Thank you!
@claudiamanta19438 ай бұрын
3:45 How do you know info about somebody’s behaviour if they use a VPN?
@kmernolimitpro78023 жыл бұрын
Thanks sir
@Byyte3 жыл бұрын
Hey I know this guy!! Lol
@claudiamanta19437 ай бұрын
Thanks for sharing, it’s really interesting. I don’t know much about IT, but isn’t it risky to use any automated system to flag up problems? Such system is only as good as its algorithms and the way the administrator configures it. Re the incident. Maybe this lady works remotely from Ukraine? Last but not least, shouldn’t the company’s IT admin check her activity? Please, tell me that Admins can do that despite the employees using VPN, otherwise the system would be safe-ish from external attacks but totally vulnerable to internal attacks. Thanks.
@KJC20253 жыл бұрын
You gonna jam on that bass or not?
@SoulJah8762 жыл бұрын
Incident response without a SIEM - is it even possible?
@KeatronEvans2 жыл бұрын
I mean it's tough in an enterprise environment, but I guess anything is possible. The question is, can you do EFFECTIVE incident response without a SIEM in an enterprise environment.
@SoulJah8762 жыл бұрын
@@KeatronEvans good point. I mentioned SIEM to a manager recently but our discussion came to the fact that the team didn't have anyone to constantly monitor the system and then act/report on anomalies.
@fromthemoonandmybed Жыл бұрын
Watching this in 2023 and seeing 3:55 is wild 😭
@madhav7662 жыл бұрын
Is that windows XP?
@MinaBrinzo Жыл бұрын
Didnt work for me
@amrayoub35083 жыл бұрын
I didn't understand where and why did you got the memory dump?
@oscaroska76133 жыл бұрын
How did he get into victim device
@dharunkanna103 жыл бұрын
memory dump is got from windows machine and if u notice that the windows machine doesn't shown the evil process while seeing through command prompt. But the process is running , so we get information about the evil process running by dumping the memory using tool. and we analyze the memory dump file in kali
@igu6422 жыл бұрын
❤❤❤❤
@tomeshuggah3 жыл бұрын
That damn Barbara!
@faikerdogan28022 жыл бұрын
is that windows 7 :o
@WizardMoDz2 жыл бұрын
Like
@HavokR5052 жыл бұрын
why wouldn't u just ask her if she VPN'ed from Ukraine? ":hi, yea were u in ukraine yesterday? no? did u have a VPN on that was pointing to Ukraine? no?" hmmm
@youtubsux-z4f18 күн бұрын
It's always the HR lady :(
@derrick.Eth13 жыл бұрын
👆👆👆👆👆HE SAVE MY FILE AND DECRYPT IT.HE’S THE BEST HACKER IN THE WORLD !!!
@MrEmityushkin3 жыл бұрын
+
@hannakorostelova11802 жыл бұрын
It's Ukraine, not the Ukraine.
@TestUser-i6z Жыл бұрын
SuperCybex can provide a cyber defense services for businesses with 50-5000 employees throughout the US to help identify cyber threats and mitigate the risks. Whether your business needs firewalls, network upgrades, or cyber defense and training, we can provide a complete solution including Incident Response