SOC 101: Real-time Incident Response Walkthrough

  Рет қаралды 211,000

Exabeam

Exabeam

Күн бұрын

Пікірлер: 154
@rmcgraw7943
@rmcgraw7943 2 жыл бұрын
Been an Ent Architect for 25+ yrs and that’s the best clearest, most concise explanation of determining how best to find hidden processes on computers. Thanks.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@sielecassharpe678
@sielecassharpe678 10 ай бұрын
As a new soc analyst, I found this video very valuable! I got so much insight in such a short amount of time as well as how you should investigate and look into activities. Thanks a ton!
@laureanocavallo2476
@laureanocavallo2476 3 жыл бұрын
I felt this 12 minutes like 5 minutes. That's when you can tell it's a good video. Entertaining, informative and educational.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks for watching!
@muhammadsaeed-ks2xn
@muhammadsaeed-ks2xn Жыл бұрын
ّ 😊چ ۃ ۃچ ےچج ّچجچچچ ځ، چ ځ ّچ ّ ّ ّ ّجک ځ ّ،کجکج Ooo
@x0rZ15t
@x0rZ15t 3 жыл бұрын
Finally, a real look into the trenches of SOC and IR. Please keep up a good work!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@MereAYT
@MereAYT Жыл бұрын
This is great. It is rare to find such a good walkthrough on this stuff. Thanks!
@johnpiernicky8674
@johnpiernicky8674 2 жыл бұрын
I'm trying to get a job as a SOC Analyst Tier 1. I was told that Exabeam was used in addition to Splunk. I am grateful for these videos as they really give a good demonstration and let the viewer see how this works. The dashboard looks great and user friendly, and the ability to move from the dashboard to investigating the alert is a nice thing to see.
@FracturesHD
@FracturesHD 4 жыл бұрын
This was an amazing video! I recently got a job as a IR team member after a few years of being a network analyst. Although I have the foundations, I am very new to the job itself so this type of video helps me so much! I will definitely be subscribing!
@wilfredoperez1804
@wilfredoperez1804 4 жыл бұрын
How long have you been doing IT? Do you recommend any certs?
@ExabeamSIEM
@ExabeamSIEM 4 жыл бұрын
We're so glad you found it useful!
@FracturesHD
@FracturesHD 4 жыл бұрын
@@wilfredoperez1804 I've been in the field about 10 years total now if you include education. I currently only have my CompTIA Sec+ and Net+ but for some reason HR departments love those. I don't think they're worth all that much personally, but the amount of offers I got after getting my Sec+ was crazy. I also would recommend looking into the GIAC certifications if you are getting serious about this sort of stuff! I hope you are able to make it into the field easily!
@gopim6142
@gopim6142 3 жыл бұрын
Could you please give me your contact number, am also trying to soc analyst
@nicksmith5400
@nicksmith5400 3 жыл бұрын
Why does this only have 1.5k views? Great walkthrough sir.
@ExabeamSIEM
@ExabeamSIEM 3 жыл бұрын
Trending upward!
@okeyokafor648
@okeyokafor648 3 жыл бұрын
It has 20k views now.
@kharikyle3610
@kharikyle3610 3 жыл бұрын
Sorry to be so offtopic but does anyone know of a tool to log back into an instagram account..? I stupidly forgot my password. I appreciate any help you can give me.
@nasirkyng6766
@nasirkyng6766 3 жыл бұрын
@Khari Kyle Instablaster =)
@kharikyle3610
@kharikyle3610 3 жыл бұрын
@Nasir Kyng thanks so much for your reply. I got to the site thru google and Im in the hacking process now. Seems to take quite some time so I will reply here later with my results.
@draperw86
@draperw86 Жыл бұрын
Dang Keatron you break it down like this was a sermon !! This is awesome
@miloboy55
@miloboy55 Жыл бұрын
I’m only 4:18 in and I must say this is an excellent video.
@WilliamSalisbury
@WilliamSalisbury 3 жыл бұрын
Exactly the kind of content I needed!! Thanks a billion
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@daslynhug8953
@daslynhug8953 Жыл бұрын
Whew would recommend this video to anyone! Thank you for a value add!
@dgmckenzie11
@dgmckenzie11 3 жыл бұрын
Good content! I look forward to part 2.
@threadripper3750
@threadripper3750 2 жыл бұрын
A+ material. i will be ready for my upcoming table top exercise. Thanks a bundle!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@tinatwintinny1205
@tinatwintinny1205 11 ай бұрын
Thank you for sharing. I have been trying to get an entry-level job as a SOC, and 😐it's an exciting role.
@xCheddarB0b42x
@xCheddarB0b42x Жыл бұрын
This was excellent: short, informative, and clear. Thank you!
@mml1224
@mml1224 3 жыл бұрын
great job, esp.2prep 4 interviews this was handy, keep it comin, youll get 1m subs
@libnatty1862
@libnatty1862 2 жыл бұрын
Thanks for the great behind the scenes look into SIEM monitoring. It's sad that I have a degree from a technical college, and there were hardly any labs, just all theory. I naturally have an investigative mindset so this really intrigues me and I would love to get back into training. Keatron, where does one start?
@Foxy10-b6n
@Foxy10-b6n 3 жыл бұрын
just getting in and this was fun to watch
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks for watching!
@brianphamtv6916
@brianphamtv6916 Жыл бұрын
This is the content I’m looking for earned subscriber 🎉
@_amintrouble
@_amintrouble 2 жыл бұрын
Hi, thanks for the video. Although you mentioned it, using the md5 command is a lot better and quicker as it gives you the instant hash which you can copy and paste into VT.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@emmanueleniade7558
@emmanueleniade7558 2 жыл бұрын
Please I have a question. Is security+ course okay for new Comer into cyber security
@jackchn23
@jackchn23 Жыл бұрын
Thanks Keatron! Subbed to YOUR channel!
@dutchhome1212
@dutchhome1212 3 жыл бұрын
Great vid m8! If I may make 2 suggestions (you might already know...): if you first do the RAM memdump be4 using netstat and so on, you wont throw something out of the RAM because you just used two programs. Second, you can also upload a hash of the rootkit to VirusTotal and not the file itself, so not to alert anyone... All in all a great and informative video! Keep up the good work!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Doing a memdump required putting something external on the machine, running netstat did not. The memory dump is far more disruptive than running netstat which is local. Thanks for watching!
@shafiiqbal631
@shafiiqbal631 2 жыл бұрын
what should be the design or architecture of a SOC Center? Please provide and assist my new SOC Center.
@KishorKumar-z8e
@KishorKumar-z8e 5 ай бұрын
thanks a lot for valuable video please keep doing such a videos very informative. thanks again.
@jordanbourcier2424
@jordanbourcier2424 2 жыл бұрын
Great video!!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks!
@Jo-nw2lf
@Jo-nw2lf 2 жыл бұрын
Great video but i tried to download the exabeam but cant. do i have to pay for full download?
@RichfieldFearless
@RichfieldFearless 2 жыл бұрын
This was very educative .
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@cecilkimaro1486
@cecilkimaro1486 2 жыл бұрын
It’s a good video. Thank you for giving us a light on this matter.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@cedricroberts4336
@cedricroberts4336 3 жыл бұрын
Thank you so much for this insightful video.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@natashataylor7531
@natashataylor7531 2 жыл бұрын
Great video! Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@brittb7766
@brittb7766 3 жыл бұрын
This was an awesome video
@KeatronEvans
@KeatronEvans 3 жыл бұрын
Thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you
@MrBitviper
@MrBitviper 2 жыл бұрын
awesome video. thanks for the detailed explanation
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@rrw1981
@rrw1981 3 жыл бұрын
Great video
@TrackMonkey327
@TrackMonkey327 3 жыл бұрын
That was a great video. I learned a lot. Thank you so much for posting this.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@TenMinuteKQL
@TenMinuteKQL 3 жыл бұрын
You have an alert suggesting there may be an issue, but it was not clear that something was definitively wrong. This is the investigative process for the INV team. Once you know it is a true positive and worthy of time for containment and analysis by a dedicated team (impact to organization) it is then transferred to IR. At least in my experience. This is a good rundown of a tier 2 INV investigation.
@Whatthellisthisthing
@Whatthellisthisthing 3 жыл бұрын
Great demonstration, thank you!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@marcschweiz
@marcschweiz 3 жыл бұрын
Absolutely fantastic info
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@MohammadAliKhalil
@MohammadAliKhalil 2 жыл бұрын
This looks difficult to do all of these steps, what type of position do this type of work
@KeatronEvans
@KeatronEvans 2 жыл бұрын
It's not difficult, just takes practice.
@msudex
@msudex 3 жыл бұрын
Hello. Why we did not see that connections/processes on a victim's machine? Was the rootkit hiding that and only having a dump outside of the victims' machine made the rootkit not interfere the proper outcome of connection/processes?
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Yes, the rootkit was not allowing Windows to "show" you the connections.
@BarCast101
@BarCast101 Жыл бұрын
this is a good staff, How to do it on kubernetes?
@Mustafa-bd3db
@Mustafa-bd3db 3 жыл бұрын
Is this open source? I would like to practice
@kevincastillo9207
@kevincastillo9207 3 жыл бұрын
I wasn't aware Victor Wooten was into cyber security!
@KeatronEvans
@KeatronEvans 3 жыл бұрын
Awesome comment! I've been playing since I was a kid.
@vivekprajapati4787
@vivekprajapati4787 3 жыл бұрын
Is RSA security analytics siem tool good?
@laanbarehamza1024
@laanbarehamza1024 3 жыл бұрын
Amazing video. Thanks so much
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you for watching!
@ishwaryanarayan1010
@ishwaryanarayan1010 Жыл бұрын
Sir your videos are great . I am looking for trial version to update my skills . Do you offer free trial version?
@EdwardAmarh-01
@EdwardAmarh-01 2 жыл бұрын
Wow this was so informative. I really needed it, same question bothered me, how do you know when to dig deeper into an alert. Thanks
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@amechi
@amechi 2 жыл бұрын
Excellent 👍🏾
@ABDULBASIT-q8m7f
@ABDULBASIT-q8m7f 5 ай бұрын
what is the software used @ 7.50 ?
@zacherymahoney12
@zacherymahoney12 Жыл бұрын
Just super cool. This is why its so fun
@ekomeebahcollins4340
@ekomeebahcollins4340 3 жыл бұрын
Really great. I appreciate honestly
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@manfrombritain6816
@manfrombritain6816 3 жыл бұрын
great video!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thanks!
@jeffnaval4894
@jeffnaval4894 Жыл бұрын
It looks simple. not too much coding. Finally i have a dreamjob i'm dreaming about.
@lilmamagc
@lilmamagc 2 жыл бұрын
Wow this was so helpful
@Ray-p8d
@Ray-p8d 6 ай бұрын
How to resolve this one?
@renelvital
@renelvital 2 жыл бұрын
Thank you for the video.
@emreybs2563
@emreybs2563 2 жыл бұрын
Thanks. Very useful.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@juliusweston8036
@juliusweston8036 11 ай бұрын
Awesome Stuff!
@toliskoutovas7267
@toliskoutovas7267 Жыл бұрын
Trying to get into SOC T1. What if instead of uploading the rootkit executable on VirusTotal, you instead extracted its hash and compared it to the virustotal database? Wouldn't that be safer?
@akotamaki3385
@akotamaki3385 Жыл бұрын
Great video thank you
@mannym8ker
@mannym8ker 3 жыл бұрын
really useful, thanks bro
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Thank you!
@fromthemoonandmybed
@fromthemoonandmybed Жыл бұрын
Watching this in 2023 and seeing 3:55 is wild 😭
@Ultimah
@Ultimah 3 жыл бұрын
fanstatic video please make more video tutorials.
@KeatronEvans
@KeatronEvans 2 жыл бұрын
Will do, thanks!
@PaulEllisBIGDATA
@PaulEllisBIGDATA 3 жыл бұрын
Outstanding!!!!
@KeatronEvans
@KeatronEvans 2 жыл бұрын
You're outstanding! Thank you!
@jksalamon
@jksalamon Жыл бұрын
Wanted to check on SOC. Can there be an IT SOC and an OT SOC. Is it right to say so. Or is it just one SOC and have a SIEM separately for IT and OT. In one of our groups we had this endless debate about SOC, each side backed with their own experience and opinions. What do you think is the right approach, any document/whitepaper you can share that you know of.
@cipher4047
@cipher4047 4 жыл бұрын
Hi, if you don't use virustotal to identify malware, what commercial tool do you use? Also, please make more videos. I will support the channel!
@zak1686
@zak1686 Жыл бұрын
Thank you %100 works
@mohittyagi2691
@mohittyagi2691 2 жыл бұрын
dude tNice tutorials is super good! subbed
@gradseven7996
@gradseven7996 2 жыл бұрын
Can you make more videos like this please
@BrookeThePersonalTrainer
@BrookeThePersonalTrainer 3 ай бұрын
thank you!
@kevinmcguinness6526
@kevinmcguinness6526 Жыл бұрын
Thanks man
@raveollorza1877
@raveollorza1877 2 жыл бұрын
ITS REALLY WORKED LOL THANK YOU DUDE
@kmernolimitpro7802
@kmernolimitpro7802 3 жыл бұрын
Thanks sir
@madhav766
@madhav766 3 жыл бұрын
Is that windows XP?
@prachivirkud7286
@prachivirkud7286 2 жыл бұрын
Thank you!
@MinaBrinzo
@MinaBrinzo Жыл бұрын
Didnt work for me
@emmanuelanosike2208
@emmanuelanosike2208 2 жыл бұрын
GENIUS
@Byyte
@Byyte 3 жыл бұрын
Hey I know this guy!! Lol
@SoulJah876
@SoulJah876 2 жыл бұрын
Incident response without a SIEM - is it even possible?
@KeatronEvans
@KeatronEvans 2 жыл бұрын
I mean it's tough in an enterprise environment, but I guess anything is possible. The question is, can you do EFFECTIVE incident response without a SIEM in an enterprise environment.
@SoulJah876
@SoulJah876 2 жыл бұрын
@@KeatronEvans good point. I mentioned SIEM to a manager recently but our discussion came to the fact that the team didn't have anyone to constantly monitor the system and then act/report on anomalies.
@KJC2025
@KJC2025 3 жыл бұрын
You gonna jam on that bass or not?
@amrayoub3508
@amrayoub3508 3 жыл бұрын
I didn't understand where and why did you got the memory dump?
@oscaroska7613
@oscaroska7613 3 жыл бұрын
How did he get into victim device
@dharunkanna10
@dharunkanna10 3 жыл бұрын
memory dump is got from windows machine and if u notice that the windows machine doesn't shown the evil process while seeing through command prompt. But the process is running , so we get information about the evil process running by dumping the memory using tool. and we analyze the memory dump file in kali
@faikerdogan2802
@faikerdogan2802 2 жыл бұрын
is that windows 7 :o
@igu642
@igu642 2 жыл бұрын
❤❤❤❤
@tomeshuggah
@tomeshuggah 3 жыл бұрын
That damn Barbara!
@youtubsux-z4f
@youtubsux-z4f 2 ай бұрын
It's always the HR lady :(
@derrick.Eth1
@derrick.Eth1 3 жыл бұрын
👆👆👆👆👆HE SAVE MY FILE AND DECRYPT IT.HE’S THE BEST HACKER IN THE WORLD !!!
@HavokR505
@HavokR505 2 жыл бұрын
why wouldn't u just ask her if she VPN'ed from Ukraine? ":hi, yea were u in ukraine yesterday? no? did u have a VPN on that was pointing to Ukraine? no?" hmmm
@WizardMoDz
@WizardMoDz 2 жыл бұрын
Like
@hannakorostelova1180
@hannakorostelova1180 3 жыл бұрын
It's Ukraine, not the Ukraine.
@MrEmityushkin
@MrEmityushkin 3 жыл бұрын
+
@TestUser-i6z
@TestUser-i6z Жыл бұрын
SuperCybex can provide a cyber defense services for businesses with 50-5000 employees throughout the US to help identify cyber threats and mitigate the risks. Whether your business needs firewalls, network upgrades, or cyber defense and training, we can provide a complete solution including Incident Response
@claudiamanta1943
@claudiamanta1943 9 ай бұрын
3:45 How do you know info about somebody’s behaviour if they use a VPN?
@claudiamanta1943
@claudiamanta1943 9 ай бұрын
Thanks for sharing, it’s really interesting. I don’t know much about IT, but isn’t it risky to use any automated system to flag up problems? Such system is only as good as its algorithms and the way the administrator configures it. Re the incident. Maybe this lady works remotely from Ukraine? Last but not least, shouldn’t the company’s IT admin check her activity? Please, tell me that Admins can do that despite the employees using VPN, otherwise the system would be safe-ish from external attacks but totally vulnerable to internal attacks. Thanks.
@Hotchoclate5444
@Hotchoclate5444 Жыл бұрын
Great video!!
What Are Insider Threats and How Do We Classify Them?
5:33
CertMike Explains Incident Response Process
11:54
Mike Chapple
Рет қаралды 13 М.
黑天使被操控了#short #angel #clown
00:40
Super Beauty team
Рет қаралды 61 МЛН
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
СИНИЙ ИНЕЙ УЖЕ ВЫШЕЛ!❄️
01:01
DO$HIK
Рет қаралды 3,3 МЛН
Try this prank with your friends 😂 @karina-kola
00:18
Andrey Grechka
Рет қаралды 9 МЛН
Incident Response: Azure Log Analysis
19:15
John Hammond
Рет қаралды 67 М.
Cybersecurity SOC Analyst Lab - Email Analysis (Phishing)
25:33
Mock Interview |  Cyber Security Analyst | What is Incident Response?
15:28
What is a SIEM solution? How SIEM works and Architecture?
27:34
Relative Security
Рет қаралды 112 М.
A TYPICAL Day in the LIFE of a SOC Analyst
1:01:55
TechTual Chatter
Рет қаралды 128 М.
Splunk Tutorial for Beginners (Cyber Security Tools)
12:22
Jon Good
Рет қаралды 240 М.
Security Operations Center (SOC) Explained
5:47
IBM Technology
Рет қаралды 92 М.
для всей семьи
0:56
Стакановец
Рет қаралды 191 М.
Это лютый угар 🤣 | приколы Арсен Симонян
0:14
Арсен Симонян
Рет қаралды 294 М.
Таким раствором работать одно удовольствие
1:00
Профессия созидатели
Рет қаралды 954 М.
Satisfying Vend 😦 Ep.5 #shorts #satisfying #vendingmachine
0:23
TYE Arcade
Рет қаралды 17 МЛН
СИЖУ БЕЗ ЕДЫ, ПЬЮ ОДНУ ВОДИЧКУ.
21:37
Быть Добру
Рет қаралды 79 М.
Самые простые строительные леса
0:54
Канал ИДЕЙ
Рет қаралды 1 МЛН