Security Onion - SIMGA - Atomic Red Team

  Рет қаралды 864

cyberlabz

cyberlabz

Күн бұрын

In this video I'll demo how you can use Atomic Red Team scripts to test Security Onion Playbook Rules via SIMGA. The Onion sees all!
-Dumping Creds
-Malicious scheduled tasks
-Account creation
SIGMA is very powerful! Combined with Playbook in Security Onion the flexibility is endless! Hope you all enjoy!
#AtomicRedTeam
#SecurityOnion
github.com/red...

Пікірлер: 4
@SkreenGG
@SkreenGG 2 жыл бұрын
Great video! Dude, you are a man blessed with vision. I would never have thought of using ART to help test/tune detection plays. This is awesome! Want to pick your brain at some point about osquery
@cyberlabz
@cyberlabz 2 жыл бұрын
Thanks! All I need to do is figure out how to make better videos! ART has opened me opened up to creating more SIGMA rules which currently are not in Playbook. I hope to demo that in my next video. Stay tuned!
@SkreenGG
@SkreenGG 2 жыл бұрын
I had issues running ART in my lab but I placed the folder with all the attacks on defenders exclusion list and it worked better
@cyberlabz
@cyberlabz 2 жыл бұрын
Definitely disable Defender! The ability to choose a specific tactic, test, and repeat makes this a great tuning methodology.
Hunt Empire Outlook Malware with Security Onion 2
27:15
cyberlabz
Рет қаралды 251
DID A VAMPIRE BECOME A DOG FOR A HUMAN? 😳😳😳
00:56
Ouch.. 🤕⚽️
00:25
Celine Dept
Рет қаралды 12 МЛН
REAL 3D brush can draw grass Life Hack #shorts #lifehacks
00:42
MrMaximus
Рет қаралды 11 МЛН
Security Onion and Elastic XDR
41:38
cyberlabz
Рет қаралды 1,6 М.
How to Use Atomic Red Team Tests
7:40
Red Canary
Рет қаралды 24 М.
CyberLabz Attack Range Part 1
20:22
cyberlabz
Рет қаралды 655
Malware Traffic and CyberChef Magic - 2021-08-19
15:06
Security Onion
Рет қаралды 3,9 М.
Intel's weapon against motherboard companies... will it work?
17:26
JayzTwoCents
Рет қаралды 159 М.
Wazuh Test with Atomic Red Team
36:39
Aldi Bagus Sasmita
Рет қаралды 356
Become a bash scripting pro - full course
36:00
CODE IS EVERYTHING
Рет қаралды 62 М.
Bootstrap your Network Security Monitoring with Security Onion
10:54
Attack Detect Defend (rot169)
Рет қаралды 11 М.
The NGINX Crash Course
50:53
Laith Academy
Рет қаралды 492 М.
DID A VAMPIRE BECOME A DOG FOR A HUMAN? 😳😳😳
00:56