Open Source Incident Response Platform - Your SOC Needs This!

  Рет қаралды 36,812

Taylor Walton

Taylor Walton

Күн бұрын

Пікірлер: 38
@rockdarko440
@rockdarko440 2 жыл бұрын
What I really enjoy about your content is that you don't only show solutions but really go in-depth in them and demonstrate how they apply in the real world. What would be really awesome is a video on the different solutions you go over on your channel and explain different ways they complement each other. Thanks again man!
@deepaknarayanan3619
@deepaknarayanan3619 2 жыл бұрын
Your videos are unique and extremely useful. Great Contents , please do continue with more SOC related contents. I'm a senior cybersecurity engineer and your videos helps my team alot. All the best brother..
@FreeSOC-de
@FreeSOC-de 2 жыл бұрын
Hi Taylor, looks very interesting - is it possible to archive closed cases to MISP and is it directly usable to analyse with cortex, or did i have to use shuffle for interact between Wazuh, Cortex, MISP and DFIR-ISIS?
@cesars.3210
@cesars.3210 7 ай бұрын
Hello, did you do a video about shuffle automation with IRIS ?
@mit0w
@mit0w 2 күн бұрын
Love your videos btw
@user-um3sy6qj4c
@user-um3sy6qj4c 2 жыл бұрын
Hopefully you will demonstrate how to create a customized Incident Report Template by using DFIR-IRIS. Thanks
@mauriciob3334
@mauriciob3334 Жыл бұрын
I think knowing that cortex is still open source it would be nice to create a connection between iris and cortex
@user-um3sy6qj4c
@user-um3sy6qj4c 2 жыл бұрын
Thank you, very helpful information
@ithiou92
@ithiou92 2 жыл бұрын
Great This tool is very useful 👍👍 Can we integrate with ELK?
@logicbypass
@logicbypass 2 жыл бұрын
Hi, thx for the video, as always enjoy your content! Did you know of any self-hosted solutions that are as complex as Microsoft 365 Defender stack? (Sentinel,MDE,MDI,MDO,MDC,MDCA,AAD,DLP,TIP,MDAV..). Closer to the "Zero Trust" concept than "Network-Based Security". Thx.
@vector1one
@vector1one 2 жыл бұрын
This is cool, I was looking for a thehive replacement. Is there a tie in for intelowl much like the hive has cortex?
@alimachiavelli8917
@alimachiavelli8917 Жыл бұрын
Good one @Taylor
@S0GE_KING
@S0GE_KING 9 ай бұрын
How much memory do I need to allocate on the server for it??
@lucasvalentelima7331
@lucasvalentelima7331 2 жыл бұрын
Your terminal looks amazing! 😮 What software is it?
@MADhatter_AIM
@MADhatter_AIM 2 жыл бұрын
i want to know this also, i saw auto-complete etc ...
@brokstine
@brokstine Жыл бұрын
Termius
@da2ricky
@da2ricky Жыл бұрын
I was digging through comments to find this out myself
@markverstappen1365
@markverstappen1365 Жыл бұрын
Great video!!! Could you also make a (step-by-step) video how to get it working when someone is using Portainer as containermanagement software. Can't get it to work due to the use of all the interconnected Dockerfiles and scripts. All the images need to be constructed and then in one docker-compose file without all the seperate buildsteps you can start them in Portainer under stacks. But could not get it to work 😞
@llfrater19
@llfrater19 Ай бұрын
Sorry, the page you are looking for is currently unavailable. Please try again later. If you are the system administrator of this resource then you should check the error log for details. Faithfully yours, nginx.
@lyledocherty4356
@lyledocherty4356 Жыл бұрын
Hi There, Wondering if anyone would be able to assist me with something, I have had some struggled with DFIR IRIS and getting it up and running but I have now managed to get it working, however when I try to find the admin password to sign into the portal it states: WARNING :: post_init :: create_safe_admin :: >>> Administrator already exists Wondering if anyone else had come across this and what they did to fix it, I can't seem to see a log of the admin password anywhere, I have checked the docker logs and still don't appear to see it it just states Administrator already exists, any help is much appreciated.
@ak414414
@ak414414 Жыл бұрын
Can ElastAlert send alert to DFIR-IRIS ?
@bdcirt6125
@bdcirt6125 Жыл бұрын
Nice tutorial :) How to post the elastalerts from praeco to iris?
@ICanEatThat
@ICanEatThat 2 жыл бұрын
Does IRIS support multi tenants like TheHive, would be so cool if it does
@KimHalavakoski
@KimHalavakoski Жыл бұрын
Yes it does.
@kader8815
@kader8815 9 ай бұрын
can i use dfir-iris without docker ??
@JorgeAntonioArca
@JorgeAntonioArca 2 жыл бұрын
Hola, de donde sacan los eventos?
@IvanCenturionGiles
@IvanCenturionGiles 2 жыл бұрын
The tool looks very useful
@aramisdelacruz8879
@aramisdelacruz8879 8 ай бұрын
Hello, has anyone here been able to generate automatic alerts once they match with MISP or some other threat intelligence tool, using graylog for log management?
@Muhammad-re4wk
@Muhammad-re4wk 3 ай бұрын
Yes we have done this where I work
@mkhalileng
@mkhalileng Жыл бұрын
thank you for your effort. Could you make video for latest version 2.3 ? 😅
@erosonthekitchen
@erosonthekitchen Жыл бұрын
Did you manage to install version 2.3? It doesn't work for me, it won't start on port 443, it keeps telling me that the website is sleeping.
@jaimev321
@jaimev321 Жыл бұрын
Thanks
@mmahrusqusaeri1326
@mmahrusqusaeri1326 2 жыл бұрын
cool, i will try this
@cod_010
@cod_010 2 жыл бұрын
How did you get the Virus total API Key?
@ithiou92
@ithiou92 2 жыл бұрын
On virus total plateform after creating an account you can request the API key
@DeadlyDragon_
@DeadlyDragon_ Жыл бұрын
Something to note ifor others who may see this there is a rather small API limit for virustotal.
@EminKmmm
@EminKmmm Жыл бұрын
awesome
Stop Using Docker. Use Open Source Instead
12:40
DevOps Toolbox
Рет қаралды 283 М.
Мен атып көрмегенмін ! | Qalam | 5 серия
25:41
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
The Wazuh File Integrity Monitoring (FIM) Use case
32:04
MyDFIR
Рет қаралды 19 М.
the Hoarder situation is crazy
8:33
TechHut
Рет қаралды 42 М.
Gatus: Your Open-Source Website Monitoring Solution
23:16
DB Tech
Рет қаралды 9 М.
The Free and Open Source Software I Use in 2024 - Part 1
28:31
Awesome Open Source
Рет қаралды 351 М.
Open Source Security Operations - Wazuh, DFIR-IRIS, Shuffle, MISP Threat Sharing
21:08
Network Security Cloud Club
Рет қаралды 3,9 М.
Гига богатый геймер vs бедный геймер
30:55
Трум Трум Оки Токи
Рет қаралды 114 М.
НЕ ДАМ ЕЁ В ОБИДУ😡 #shorts
0:24
Паша Осадчий
Рет қаралды 1,6 МЛН
Самые простые строительные леса
0:54
Канал ИДЕЙ
Рет қаралды 1 МЛН
Лайфхак: Легально делать деньги
0:43