Security Onion Essentials 2.3 - Detection Engineering

  Рет қаралды 20,500

Security Onion

Security Onion

Күн бұрын

In this session, we cover the third and final common workflow in Security Onion - Detection Engineering.
Security Onion Essentials - Playlist: • Security Onion Essenti...
If you have questions or problems, please feel free to create a discussion at securityonion....

Пікірлер: 12
@SkreenGG
@SkreenGG 2 жыл бұрын
Great video. The playbook tool is very powerful and allows for unlimited customization. Thanks for this video!
@security-onion
@security-onion 2 жыл бұрын
Thanks, glad you like it!
@PaulBenedict22
@PaulBenedict22 2 жыл бұрын
This was an awesome way to understand detection engineering. I’m going to use and implement those 4 steps myself
@security-onion
@security-onion 2 жыл бұрын
Thanks, glad you like it!
@absemperor7095
@absemperor7095 3 жыл бұрын
very good
@security-onion
@security-onion 3 жыл бұрын
Thanks!
@faizankhd
@faizankhd 3 жыл бұрын
Do you cover ELk kibana siem to detect different network attacks, lateral movement, ransomware attack, phishing attack , incident response ,etc
@security-onion
@security-onion 3 жыл бұрын
Not sure what you're asking. Security Onion includes the Elastic stack and Kibana. You can use Kibana or our own web interfaces (Alerts and Hunt) to detect these kinds of attacks. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!
@UnwanaEssien
@UnwanaEssien Жыл бұрын
Can I write this for data source of netflow ? Being that netflow is not processed by suricata etc
@security-onion
@security-onion Жыл бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss
@lonewaffle
@lonewaffle 3 жыл бұрын
I notice that they are all set to draft by default. Would it be a bad idea to turn most of them on? How big of an impact would that have on the server?
@security-onion
@security-onion 3 жыл бұрын
From docs.securityonion.net/en/2.3/playbook.html#putting-a-play-into-production: "Performance testing is still ongoing. We recommend avoiding the Malicious Nishang PowerShell Commandlets play as it can cause serious performance problems. You may also want to avoid others with a status of experimental." If you have further questions or problems, please start a new discussion at securityonion.net/discuss Thanks!
Security Onion Essentials 2.3 -  Wrap Up
4:10
Security Onion
Рет қаралды 7 М.
Security Onion Essentials 2.3 - Ad Hoc Hunting
32:53
Security Onion
Рет қаралды 25 М.
Самое неинтересное видео
00:32
Miracle
Рет қаралды 1,2 МЛН
Zombie Boy Saved My Life 💚
00:29
Alan Chikin Chow
Рет қаралды 35 МЛН
Violet Beauregarde Doll🫐
00:58
PIRANKA
Рет қаралды 50 МЛН
小丑和白天使的比试。#天使 #小丑 #超人不会飞
00:51
超人不会飞
Рет қаралды 35 МЛН
Security Onion Essentials 2.3 - Alert Triage & Case Creation
23:13
Security Onion
Рет қаралды 23 М.
Detection as Code: Detection Development Using CI/CD
30:22
RSA Conference
Рет қаралды 5 М.
Introduction to Security Onion 2.4
46:52
Security Onion
Рет қаралды 12 М.
Threat-Informed Detection Engineering
55:08
SANS Offensive Operations
Рет қаралды 4,5 М.
Build your Detection Lab with Security Onion
21:44
Hack eXPlorer
Рет қаралды 30 М.
Information Technology In 4 Minutes
4:30
Shane Hummus
Рет қаралды 496 М.
Самое неинтересное видео
00:32
Miracle
Рет қаралды 1,2 МЛН