SOC 101: Real-time Incident Response Walkthrough

  Рет қаралды 207,096

Exabeam

Exabeam

Күн бұрын

Пікірлер: 154
@sielecassharpe678
@sielecassharpe678 8 ай бұрын
As a new soc analyst, I found this video very valuable! I got so much insight in such a short amount of time as well as how you should investigate and look into activities. Thanks a ton!
@rmcgraw7943
@rmcgraw7943 2 жыл бұрын
Been an Ent Architect for 25+ yrs and that’s the best clearest, most concise explanation of determining how best to find hidden processes on computers. Thanks.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@laureanocavallo2476
@laureanocavallo2476 3 жыл бұрын
I felt this 12 minutes like 5 minutes. That's when you can tell it's a good video. Entertaining, informative and educational.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks for watching!
@muhammadsaeed-ks2xn
@muhammadsaeed-ks2xn Жыл бұрын
ّ 😊چ ۃ ۃچ ےچج ّچجچچچ ځ، چ ځ ّچ ّ ّ ّ ّجک ځ ّ،کجکج Ooo
@MereAYT
@MereAYT Жыл бұрын
This is great. It is rare to find such a good walkthrough on this stuff. Thanks!
@x0rZ15t
@x0rZ15t 3 жыл бұрын
Finally, a real look into the trenches of SOC and IR. Please keep up a good work!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@johnpiernicky8674
@johnpiernicky8674 2 жыл бұрын
I'm trying to get a job as a SOC Analyst Tier 1. I was told that Exabeam was used in addition to Splunk. I am grateful for these videos as they really give a good demonstration and let the viewer see how this works. The dashboard looks great and user friendly, and the ability to move from the dashboard to investigating the alert is a nice thing to see.
@draperw86
@draperw86 Жыл бұрын
Dang Keatron you break it down like this was a sermon !! This is awesome
@FracturesHD
@FracturesHD 3 жыл бұрын
This was an amazing video! I recently got a job as a IR team member after a few years of being a network analyst. Although I have the foundations, I am very new to the job itself so this type of video helps me so much! I will definitely be subscribing!
@wilfredoperez1804
@wilfredoperez1804 3 жыл бұрын
How long have you been doing IT? Do you recommend any certs?
@ExabeamSIEM
@ExabeamSIEM 3 жыл бұрын
We're so glad you found it useful!
@FracturesHD
@FracturesHD 3 жыл бұрын
@@wilfredoperez1804 I've been in the field about 10 years total now if you include education. I currently only have my CompTIA Sec+ and Net+ but for some reason HR departments love those. I don't think they're worth all that much personally, but the amount of offers I got after getting my Sec+ was crazy. I also would recommend looking into the GIAC certifications if you are getting serious about this sort of stuff! I hope you are able to make it into the field easily!
@gopim6142
@gopim6142 3 жыл бұрын
Could you please give me your contact number, am also trying to soc analyst
@daslynhug8953
@daslynhug8953 Жыл бұрын
Whew would recommend this video to anyone! Thank you for a value add!
@nicksmith5400
@nicksmith5400 3 жыл бұрын
Why does this only have 1.5k views? Great walkthrough sir.
@ExabeamSIEM
@ExabeamSIEM 3 жыл бұрын
Trending upward!
@okeyokafor648
@okeyokafor648 3 жыл бұрын
It has 20k views now.
@kharikyle3610
@kharikyle3610 3 жыл бұрын
Sorry to be so offtopic but does anyone know of a tool to log back into an instagram account..? I stupidly forgot my password. I appreciate any help you can give me.
@nasirkyng6766
@nasirkyng6766 3 жыл бұрын
@Khari Kyle Instablaster =)
@kharikyle3610
@kharikyle3610 3 жыл бұрын
@Nasir Kyng thanks so much for your reply. I got to the site thru google and Im in the hacking process now. Seems to take quite some time so I will reply here later with my results.
@WilliamSalisbury
@WilliamSalisbury 3 жыл бұрын
Exactly the kind of content I needed!! Thanks a billion
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@brianphamtv6916
@brianphamtv6916 Жыл бұрын
This is the content I’m looking for earned subscriber 🎉
@jackchn23
@jackchn23 11 ай бұрын
Thanks Keatron! Subbed to YOUR channel!
@KishorKumar-z8e
@KishorKumar-z8e 3 ай бұрын
thanks a lot for valuable video please keep doing such a videos very informative. thanks again.
@xCheddarB0b42x
@xCheddarB0b42x Жыл бұрын
This was excellent: short, informative, and clear. Thank you!
@tinatwintinny1205
@tinatwintinny1205 9 ай бұрын
Thank you for sharing. I have been trying to get an entry-level job as a SOC, and 😐it's an exciting role.
@miloboy55
@miloboy55 Жыл бұрын
I’m only 4:18 in and I must say this is an excellent video.
@threadripper3750
@threadripper3750 2 жыл бұрын
A+ material. i will be ready for my upcoming table top exercise. Thanks a bundle!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@dgmckenzie11
@dgmckenzie11 3 жыл бұрын
Good content! I look forward to part 2.
@mml1224
@mml1224 3 жыл бұрын
great job, esp.2prep 4 interviews this was handy, keep it comin, youll get 1m subs
@jordanbourcier2424
@jordanbourcier2424 2 жыл бұрын
Great video!!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks!
@Foxy10-b6n
@Foxy10-b6n 3 жыл бұрын
just getting in and this was fun to watch
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks for watching!
@RichfieldFearless
@RichfieldFearless 2 жыл бұрын
This was very educative .
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@libnatty1862
@libnatty1862 2 жыл бұрын
Thanks for the great behind the scenes look into SIEM monitoring. It's sad that I have a degree from a technical college, and there were hardly any labs, just all theory. I naturally have an investigative mindset so this really intrigues me and I would love to get back into training. Keatron, where does one start?
@_amintrouble
@_amintrouble 2 жыл бұрын
Hi, thanks for the video. Although you mentioned it, using the md5 command is a lot better and quicker as it gives you the instant hash which you can copy and paste into VT.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@brittb7766
@brittb7766 3 жыл бұрын
This was an awesome video
@KeatronEvans
@KeatronEvans 3 жыл бұрын
Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you
@MrBitviper
@MrBitviper 2 жыл бұрын
awesome video. thanks for the detailed explanation
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@natashataylor7531
@natashataylor7531 2 жыл бұрын
Great video! Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@rrw1981
@rrw1981 3 жыл бұрын
Great video
@cecilkimaro1486
@cecilkimaro1486 2 жыл бұрын
It’s a good video. Thank you for giving us a light on this matter.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@cedricroberts4336
@cedricroberts4336 3 жыл бұрын
Thank you so much for this insightful video.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@marcschweiz
@marcschweiz 3 жыл бұрын
Absolutely fantastic info
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@shafiiqbal631
@shafiiqbal631 2 жыл бұрын
what should be the design or architecture of a SOC Center? Please provide and assist my new SOC Center.
@Jo-nw2lf
@Jo-nw2lf 2 жыл бұрын
Great video but i tried to download the exabeam but cant. do i have to pay for full download?
@zacherymahoney12
@zacherymahoney12 Жыл бұрын
Just super cool. This is why its so fun
@TrackMonkey327
@TrackMonkey327 3 жыл бұрын
That was a great video. I learned a lot. Thank you so much for posting this.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@amechi
@amechi 2 жыл бұрын
Excellent 👍🏾
@Whatthellisthisthing
@Whatthellisthisthing 3 жыл бұрын
Great demonstration, thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@laanbarehamza1024
@laanbarehamza1024 2 жыл бұрын
Amazing video. Thanks so much
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@emmanueleniade7558
@emmanueleniade7558 2 жыл бұрын
Please I have a question. Is security+ course okay for new Comer into cyber security
@EdwardAmarh-01
@EdwardAmarh-01 2 жыл бұрын
Wow this was so informative. I really needed it, same question bothered me, how do you know when to dig deeper into an alert. Thanks
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@msudex
@msudex 3 жыл бұрын
Hello. Why we did not see that connections/processes on a victim's machine? Was the rootkit hiding that and only having a dump outside of the victims' machine made the rootkit not interfere the proper outcome of connection/processes?
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Yes, the rootkit was not allowing Windows to "show" you the connections.
@manfrombritain6816
@manfrombritain6816 3 жыл бұрын
great video!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks!
@renelvital
@renelvital Жыл бұрын
Thank you for the video.
@dutchhome1212
@dutchhome1212 3 жыл бұрын
Great vid m8! If I may make 2 suggestions (you might already know...): if you first do the RAM memdump be4 using netstat and so on, you wont throw something out of the RAM because you just used two programs. Second, you can also upload a hash of the rootkit to VirusTotal and not the file itself, so not to alert anyone... All in all a great and informative video! Keep up the good work!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Doing a memdump required putting something external on the machine, running netstat did not. The memory dump is far more disruptive than running netstat which is local. Thanks for watching!
@ekomeebahcollins4340
@ekomeebahcollins4340 2 жыл бұрын
Really great. I appreciate honestly
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@lilmamagc
@lilmamagc 2 жыл бұрын
Wow this was so helpful
@juliusweston8036
@juliusweston8036 9 ай бұрын
Awesome Stuff!
@TenMinuteKQL
@TenMinuteKQL 3 жыл бұрын
You have an alert suggesting there may be an issue, but it was not clear that something was definitively wrong. This is the investigative process for the INV team. Once you know it is a true positive and worthy of time for containment and analysis by a dedicated team (impact to organization) it is then transferred to IR. At least in my experience. This is a good rundown of a tier 2 INV investigation.
@emreybs2563
@emreybs2563 2 жыл бұрын
Thanks. Very useful.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@ishwaryanarayan1010
@ishwaryanarayan1010 Жыл бұрын
Sir your videos are great . I am looking for trial version to update my skills . Do you offer free trial version?
@akotamaki3385
@akotamaki3385 Жыл бұрын
Great video thank you
@raveollorza1877
@raveollorza1877 2 жыл бұрын
ITS REALLY WORKED LOL THANK YOU DUDE
@mannym8ker
@mannym8ker 3 жыл бұрын
really useful, thanks bro
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@kevincastillo9207
@kevincastillo9207 3 жыл бұрын
I wasn't aware Victor Wooten was into cyber security!
@KeatronEvans
@KeatronEvans 3 жыл бұрын
Awesome comment! I've been playing since I was a kid.
@BarCast101
@BarCast101 Жыл бұрын
this is a good staff, How to do it on kubernetes?
@PaulEllisBIGDATA
@PaulEllisBIGDATA 3 жыл бұрын
Outstanding!!!!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
You're outstanding! Thank you!
@Ultimah
@Ultimah 3 жыл бұрын
fanstatic video please make more video tutorials.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Will do, thanks!
@zak1686
@zak1686 Жыл бұрын
Thank you %100 works
@MohammadAliKhalil
@MohammadAliKhalil 2 жыл бұрын
This looks difficult to do all of these steps, what type of position do this type of work
@KeatronEvans
@KeatronEvans 2 жыл бұрын
It's not difficult, just takes practice.
@vivekprajapati4787
@vivekprajapati4787 3 жыл бұрын
Is RSA security analytics siem tool good?
@toliskoutovas7267
@toliskoutovas7267 Жыл бұрын
Trying to get into SOC T1. What if instead of uploading the rootkit executable on VirusTotal, you instead extracted its hash and compared it to the virustotal database? Wouldn't that be safer?
@kevinmcguinness6526
@kevinmcguinness6526 Жыл бұрын
Thanks man
@ABDULBASIT-q8m7f
@ABDULBASIT-q8m7f 4 ай бұрын
what is the software used @ 7.50 ?
@BrookeThePersonalTrainer
@BrookeThePersonalTrainer Ай бұрын
thank you!
@Mustafa-bd3db
@Mustafa-bd3db 3 жыл бұрын
Is this open source? I would like to practice
@jksalamon
@jksalamon Жыл бұрын
Wanted to check on SOC. Can there be an IT SOC and an OT SOC. Is it right to say so. Or is it just one SOC and have a SIEM separately for IT and OT. In one of our groups we had this endless debate about SOC, each side backed with their own experience and opinions. What do you think is the right approach, any document/whitepaper you can share that you know of.
@cipher4047
@cipher4047 3 жыл бұрын
Hi, if you don't use virustotal to identify malware, what commercial tool do you use? Also, please make more videos. I will support the channel!
@Ray-p8d
@Ray-p8d 5 ай бұрын
How to resolve this one?
@mohittyagi2691
@mohittyagi2691 2 жыл бұрын
dude tNice tutorials is super good! subbed
@jeffnaval4894
@jeffnaval4894 10 ай бұрын
It looks simple. not too much coding. Finally i have a dreamjob i'm dreaming about.
@gradseven7996
@gradseven7996 2 жыл бұрын
Can you make more videos like this please
@emmanuelanosike2208
@emmanuelanosike2208 2 жыл бұрын
GENIUS
@prachivirkud7286
@prachivirkud7286 2 жыл бұрын
Thank you!
@claudiamanta1943
@claudiamanta1943 8 ай бұрын
3:45 How do you know info about somebody’s behaviour if they use a VPN?
@kmernolimitpro7802
@kmernolimitpro7802 3 жыл бұрын
Thanks sir
@Byyte
@Byyte 3 жыл бұрын
Hey I know this guy!! Lol
@claudiamanta1943
@claudiamanta1943 7 ай бұрын
Thanks for sharing, it’s really interesting. I don’t know much about IT, but isn’t it risky to use any automated system to flag up problems? Such system is only as good as its algorithms and the way the administrator configures it. Re the incident. Maybe this lady works remotely from Ukraine? Last but not least, shouldn’t the company’s IT admin check her activity? Please, tell me that Admins can do that despite the employees using VPN, otherwise the system would be safe-ish from external attacks but totally vulnerable to internal attacks. Thanks.
@KJC2025
@KJC2025 3 жыл бұрын
You gonna jam on that bass or not?
@SoulJah876
@SoulJah876 2 жыл бұрын
Incident response without a SIEM - is it even possible?
@KeatronEvans
@KeatronEvans 2 жыл бұрын
I mean it's tough in an enterprise environment, but I guess anything is possible. The question is, can you do EFFECTIVE incident response without a SIEM in an enterprise environment.
@SoulJah876
@SoulJah876 2 жыл бұрын
@@KeatronEvans good point. I mentioned SIEM to a manager recently but our discussion came to the fact that the team didn't have anyone to constantly monitor the system and then act/report on anomalies.
@fromthemoonandmybed
@fromthemoonandmybed Жыл бұрын
Watching this in 2023 and seeing 3:55 is wild 😭
@madhav766
@madhav766 2 жыл бұрын
Is that windows XP?
@MinaBrinzo
@MinaBrinzo Жыл бұрын
Didnt work for me
@amrayoub3508
@amrayoub3508 3 жыл бұрын
I didn't understand where and why did you got the memory dump?
@oscaroska7613
@oscaroska7613 3 жыл бұрын
How did he get into victim device
@dharunkanna10
@dharunkanna10 3 жыл бұрын
memory dump is got from windows machine and if u notice that the windows machine doesn't shown the evil process while seeing through command prompt. But the process is running , so we get information about the evil process running by dumping the memory using tool. and we analyze the memory dump file in kali
@igu642
@igu642 2 жыл бұрын
❤❤❤❤
@tomeshuggah
@tomeshuggah 3 жыл бұрын
That damn Barbara!
@faikerdogan2802
@faikerdogan2802 2 жыл бұрын
is that windows 7 :o
@WizardMoDz
@WizardMoDz 2 жыл бұрын
Like
@HavokR505
@HavokR505 2 жыл бұрын
why wouldn't u just ask her if she VPN'ed from Ukraine? ":hi, yea were u in ukraine yesterday? no? did u have a VPN on that was pointing to Ukraine? no?" hmmm
@youtubsux-z4f
@youtubsux-z4f 18 күн бұрын
It's always the HR lady :(
@derrick.Eth1
@derrick.Eth1 3 жыл бұрын
👆👆👆👆👆HE SAVE MY FILE AND DECRYPT IT.HE’S THE BEST HACKER IN THE WORLD !!!
@MrEmityushkin
@MrEmityushkin 3 жыл бұрын
+
@hannakorostelova1180
@hannakorostelova1180 2 жыл бұрын
It's Ukraine, not the Ukraine.
@TestUser-i6z
@TestUser-i6z Жыл бұрын
SuperCybex can provide a cyber defense services for businesses with 50-5000 employees throughout the US to help identify cyber threats and mitigate the risks. Whether your business needs firewalls, network upgrades, or cyber defense and training, we can provide a complete solution including Incident Response
@Hotchoclate5444
@Hotchoclate5444 Жыл бұрын
Great video!!
What Are Insider Threats and How Do We Classify Them?
5:33
Cybersecurity SOC Analyst Lab - Email Analysis (Phishing)
25:33
小路飞和小丑也太帅了#家庭#搞笑 #funny #小丑 #cosplay
00:13
家庭搞笑日记
Рет қаралды 9 МЛН
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 33 МЛН
Миллионер | 3 - серия
36:09
Million Show
Рет қаралды 2,2 МЛН
CertMike Explains Incident Response Process
11:54
Mike Chapple
Рет қаралды 12 М.
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,3 МЛН
Incident Response: Azure Log Analysis
19:15
John Hammond
Рет қаралды 66 М.
Mock Interview |  Cyber Security Analyst | What is Incident Response?
15:28
Cybersecurity: SOC Analyst Mini-Course (Training)
56:45
MyDFIR
Рет қаралды 72 М.
DON’T Start Cybersecurity - Do THIS instead
10:33
Tech With Soleyman
Рет қаралды 57 М.
Incident Response Plan based on NIST- Daniel's Security Academy
16:05
Daniel's Security Academy
Рет қаралды 5 М.
What does an Incident Response Consultant Do?
8:28
IBM Technology
Рет қаралды 5 М.
小路飞和小丑也太帅了#家庭#搞笑 #funny #小丑 #cosplay
00:13
家庭搞笑日记
Рет қаралды 9 МЛН