Hack The Box SOC Analyst Lab - Unit42 (Sysmon)

  Рет қаралды 4,328

MyDFIR

MyDFIR

Күн бұрын

Пікірлер
@dlcrdz00
@dlcrdz00 10 күн бұрын
Great video walkthrough...Haven't had much experience with Splunk but this video definitely got me excited the more we dug into the Event Logs
@MyDFIR
@MyDFIR 9 күн бұрын
Glad it sparked some interest, Splunk is a powerful tool!
@RubenMuñozAragon-e9n
@RubenMuñozAragon-e9n 5 ай бұрын
Great. Please I LOVE content of Splunk. Thanks.
@MyDFIR
@MyDFIR 5 ай бұрын
More to come!
@SayoOlanbiwonnu
@SayoOlanbiwonnu 5 ай бұрын
Amazing Delivery as usual ❤
@MyDFIR
@MyDFIR 5 ай бұрын
Thank you ❤️
@anitagd
@anitagd 5 ай бұрын
Great video as usual 🔥
@MyDFIR
@MyDFIR 5 ай бұрын
Appreciate it!
@MustafaAhmedQasemYahya
@MustafaAhmedQasemYahya 3 ай бұрын
You are anazing. Very nice. Thanks
@MyDFIR
@MyDFIR 3 ай бұрын
Wow, thank you!
@aplik3
@aplik3 5 ай бұрын
I was just planning to do this room today :D Great video!
@MyDFIR
@MyDFIR 5 ай бұрын
Have fun!
@mapletech_22
@mapletech_22 5 ай бұрын
Amazing work 👏 🙌 👌 ❤
@MyDFIR
@MyDFIR 5 ай бұрын
Thank you 🙌
@irocz5150
@irocz5150 5 ай бұрын
Excellent video. Sad to say but sysmon generates lots of logs and sometimes there is a push back installing this amazing tool.
@MyDFIR
@MyDFIR 5 ай бұрын
You’re absolutely correct but there are some companies out there that have it!
@thebodythehead
@thebodythehead 5 ай бұрын
amazing video
@MyDFIR
@MyDFIR 5 ай бұрын
Thanks!
@frankurhioke1964
@frankurhioke1964 Ай бұрын
Do you have a discount on your course presently or a payment plan in place?
@MyDFIR
@MyDFIR Ай бұрын
Not yet but definitely something I plan on doing soon
@erglaligzda2265
@erglaligzda2265 5 ай бұрын
Any bright idea how to monitor end-point DNS queries? Now I am using sysmon, but not always it captures end-points IP and/or user. :(
@MyDFIR
@MyDFIR 5 ай бұрын
Strange, Sysmon Event ID 22 should capture the source IP of the endpoint and you can correlate that with other event IDs if required
@erglaligzda2265
@erglaligzda2265 5 ай бұрын
@@MyDFIR I thought so too, but on-premise environment it may not happen. Thanks for pointing out Event ID. I'll take a second into config file. :)
@MoSiraji
@MoSiraji 5 ай бұрын
Thank you good for training
@MyDFIR
@MyDFIR 5 ай бұрын
You’re welcome! Hope you had some fun and learned new things 👍
@MoSiraji
@MoSiraji 5 ай бұрын
@@MyDFIR Yes, I did.
@Whiterqbbit
@Whiterqbbit 5 ай бұрын
Fancy using Splunk, I would of probably used ZT Timeline Explorer - Going have to checkout that splunk video.
@MyDFIR
@MyDFIR 5 ай бұрын
heheh thanks! I love sifting through logs using Splunk as I can better visualize the data but I'd recommend using any tool that does the job!
@myles5253
@myles5253 5 ай бұрын
Do you use a VM for Hackthebox labs?
@godwinalekeobor5274
@godwinalekeobor5274 5 ай бұрын
You can use their VM, if you subscribe
@MyDFIR
@MyDFIR 5 ай бұрын
Any labs I do, I always use a VM. That way I can revert it pretty easily if I need to.
@Abc-sl1nf
@Abc-sl1nf 5 ай бұрын
Thx!
@ItsCynik
@ItsCynik 5 ай бұрын
wen next project? 😢
@MyDFIR
@MyDFIR 5 ай бұрын
Heheh TBD! These take a long time to do. Have you completed all of the ones on my channel?
@mariostevenquijivix5752
@mariostevenquijivix5752 5 ай бұрын
Im using a Mac. Is there another way aside from 7zip top extract the folder?
@MyDFIR
@MyDFIR 5 ай бұрын
I believe Mac has a built in extractor where you could double click and should do the trick.
@imca_b_5517
@imca_b_5517 5 ай бұрын
Brother please don't upload video of hack the box because it was not free and + we are students so we don't have enough money for that but if you make video on other Topics so I will help
@MyDFIR
@MyDFIR 5 ай бұрын
But it is free or at least portions of it. All the labs I’ve uploaded so far are free that you can do and follow along. Unless I am missing something?
Quando A Diferença De Altura É Muito Grande 😲😂
00:12
Mari Maria
Рет қаралды 45 МЛН
Мен атып көрмегенмін ! | Qalam | 5 серия
25:41
Cybersecurity: SOC Analyst Mini-Course (Training)
56:45
MyDFIR
Рет қаралды 74 М.
How to respond FAST to Incidents in Cybersecurity
11:47
Tech with Jono
Рет қаралды 6 М.
researchers find an unfixable bug in EVERY ARM cpu
9:48
Low Level
Рет қаралды 560 М.
My First Day As A SOC Analyst
10:01
Mad Hat
Рет қаралды 69 М.
How A Printer Lost A Country $81,000,000
15:58
Cipher
Рет қаралды 846 М.
I Played HackTheBox For 30 Days - Here's What I Learned
10:23
Grant Collins
Рет қаралды 489 М.