Great video walkthrough...Haven't had much experience with Splunk but this video definitely got me excited the more we dug into the Event Logs
@MyDFIR9 күн бұрын
Glad it sparked some interest, Splunk is a powerful tool!
@RubenMuñozAragon-e9n5 ай бұрын
Great. Please I LOVE content of Splunk. Thanks.
@MyDFIR5 ай бұрын
More to come!
@SayoOlanbiwonnu5 ай бұрын
Amazing Delivery as usual ❤
@MyDFIR5 ай бұрын
Thank you ❤️
@anitagd5 ай бұрын
Great video as usual 🔥
@MyDFIR5 ай бұрын
Appreciate it!
@MustafaAhmedQasemYahya3 ай бұрын
You are anazing. Very nice. Thanks
@MyDFIR3 ай бұрын
Wow, thank you!
@aplik35 ай бұрын
I was just planning to do this room today :D Great video!
@MyDFIR5 ай бұрын
Have fun!
@mapletech_225 ай бұрын
Amazing work 👏 🙌 👌 ❤
@MyDFIR5 ай бұрын
Thank you 🙌
@irocz51505 ай бұрын
Excellent video. Sad to say but sysmon generates lots of logs and sometimes there is a push back installing this amazing tool.
@MyDFIR5 ай бұрын
You’re absolutely correct but there are some companies out there that have it!
@thebodythehead5 ай бұрын
amazing video
@MyDFIR5 ай бұрын
Thanks!
@frankurhioke1964Ай бұрын
Do you have a discount on your course presently or a payment plan in place?
@MyDFIRАй бұрын
Not yet but definitely something I plan on doing soon
@erglaligzda22655 ай бұрын
Any bright idea how to monitor end-point DNS queries? Now I am using sysmon, but not always it captures end-points IP and/or user. :(
@MyDFIR5 ай бұрын
Strange, Sysmon Event ID 22 should capture the source IP of the endpoint and you can correlate that with other event IDs if required
@erglaligzda22655 ай бұрын
@@MyDFIR I thought so too, but on-premise environment it may not happen. Thanks for pointing out Event ID. I'll take a second into config file. :)
@MoSiraji5 ай бұрын
Thank you good for training
@MyDFIR5 ай бұрын
You’re welcome! Hope you had some fun and learned new things 👍
@MoSiraji5 ай бұрын
@@MyDFIR Yes, I did.
@Whiterqbbit5 ай бұрын
Fancy using Splunk, I would of probably used ZT Timeline Explorer - Going have to checkout that splunk video.
@MyDFIR5 ай бұрын
heheh thanks! I love sifting through logs using Splunk as I can better visualize the data but I'd recommend using any tool that does the job!
@myles52535 ай бұрын
Do you use a VM for Hackthebox labs?
@godwinalekeobor52745 ай бұрын
You can use their VM, if you subscribe
@MyDFIR5 ай бұрын
Any labs I do, I always use a VM. That way I can revert it pretty easily if I need to.
@Abc-sl1nf5 ай бұрын
Thx!
@ItsCynik5 ай бұрын
wen next project? 😢
@MyDFIR5 ай бұрын
Heheh TBD! These take a long time to do. Have you completed all of the ones on my channel?
@mariostevenquijivix57525 ай бұрын
Im using a Mac. Is there another way aside from 7zip top extract the folder?
@MyDFIR5 ай бұрын
I believe Mac has a built in extractor where you could double click and should do the trick.
@imca_b_55175 ай бұрын
Brother please don't upload video of hack the box because it was not free and + we are students so we don't have enough money for that but if you make video on other Topics so I will help
@MyDFIR5 ай бұрын
But it is free or at least portions of it. All the labs I’ve uploaded so far are free that you can do and follow along. Unless I am missing something?