Threat Hunting for IOCs with Elastic Stack

  Рет қаралды 17,686

Official Elastic Community

Official Elastic Community

Күн бұрын

Пікірлер: 4
@sergeydrachuk8612
@sergeydrachuk8612 3 жыл бұрын
The most valuable information in a Threat Intelligence alert is a description (context of an indicator). We had checked inside of the alert a presence of matched ioc description today (kibana 7.16.3) and it's absent. Also it's impossible to understand which IOC (document[s]) and which feed[s] triggered the alert. This lead to impossibility of an IOC pivoting and a big disappointment with the Threat Intelligence rules feature. If your developers worked as SOC analysts, they would understand this pain. Second point. There is no possibility of a custom cleaning (for example removing IP 127.0.0.1) of the feeds (exceptions is not a right way to do this). Third point. There is no any de-duplication. So if five feeds contains the same IP the query will be 5 times heavier. I know this point is not so easy to implement but possible anyway.
@MsTarguisti
@MsTarguisti 2 жыл бұрын
Hellow from marokko, appreciated!
@hamzaidris4822
@hamzaidris4822 3 жыл бұрын
Hi, I someone have bought a paid threat intelligence, how can we ingest TI from those sources?
@jameskin61
@jameskin61 3 жыл бұрын
why when I tried to map with Cisco ASA index with filebeat-* it didn't work as expected? everything was failed!
Sizing the Elastic Stack for Security Use Cases: Expert tips & Example Exercises
1:01:21
How To Setup ELK | Elastic Agents & Sysmon for Cybersecurity
14:35
John Hammond
Рет қаралды 85 М.
Every team from the Bracket Buster! Who ya got? 😏
0:53
FailArmy Shorts
Рет қаралды 13 МЛН
Jaidarman TOP / Жоғары лига-2023 / Жекпе-жек 1-ТУР / 1-топ
1:30:54
I Sent a Subscriber to Disneyland
0:27
MrBeast
Рет қаралды 104 МЛН
Cybersecurity Trends for 2025 and Beyond
16:55
IBM Technology
Рет қаралды 85 М.
Beginner's Crash Course to Elastic Stack -  Part 1: Intro to Elasticsearch and Kibana
56:42
How To Use The Elastic Stack as a SIEM - John Hubbard
1:14:17
John Hubbard
Рет қаралды 56 М.
The Anatomy of an Att&ck
7:46
IBM Technology
Рет қаралды 33 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
this Cybersecurity Platform is FREE
39:46
John Hammond
Рет қаралды 601 М.
Introduction to  Cyber Threat Hunting : SOC
24:12
Prabh Nair
Рет қаралды 31 М.
Every team from the Bracket Buster! Who ya got? 😏
0:53
FailArmy Shorts
Рет қаралды 13 МЛН