Using Defender for Endpoint for Deep Ransomware Investigation

  Рет қаралды 3,885

Jackson Felden - Cloud and Security

Jackson Felden - Cloud and Security

Күн бұрын

Пікірлер: 5
@indiramourya2406
@indiramourya2406 2 жыл бұрын
Excellent video. Thank you for uploading.
@kashifhasnain5458
@kashifhasnain5458 2 жыл бұрын
Well explained on investigation.. keep up the good work
@tandasherman1360
@tandasherman1360 11 ай бұрын
Awesome video!!
@GregThomson
@GregThomson 2 жыл бұрын
Excellent video. Nice hands on actionable learning.
@RichardGailey
@RichardGailey 2 жыл бұрын
That was one of the best deep dives in to what to do and how to react to certain alerts raised in Defender. Really liked the way that you did this. Regarding the IP addresses that were found in the Deep Analysis results; would these be good examples of addresses that you could create a KQL query for to add these IP's as IOC's for future events for all machines in the environment. Will you be doing a video n creating KQL queries in Azure and Defender (as the syntax differs) and most importantly, how to create an alert for the SOC team should any value be found in an query that you have created. One of the main issues that I am having at the moment, is trying to create alerts from queries that I have found online and also trying to figure out how to get an action to run when an alert is triggered, like Isolate the device instantly of a severe issue is found at 03:00hrs and we don't have a 24hr SOC. Liked and subbed. Awesome video.
How to detect files containing clear text passwords
8:56
Jackson Felden - Cloud and Security
Рет қаралды 4,6 М.
6.2 Ransomware attack investigation, MDE from Zero to Hero
53:23
Jackson Felden - Cloud and Security
Рет қаралды 1,5 М.
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Automated Investigation and Response | Virtual Ninja Training with Heike Ritter
29:26
Microsoft Security Community
Рет қаралды 5 М.
6.1 Alerts & incidents management, MDE from Zero to Hero
25:27
Jackson Felden - Cloud and Security
Рет қаралды 2,4 М.
Investigation Capabilities in M365 Defender | Virtual Ninja Training with Heike Ritter
28:49
Defender for Office 365 Threat Policies Explained
28:17
Cloud Scholars
Рет қаралды 1,7 М.
1.1 Minimum requirements and licensing, MDE from Zero to Hero
19:31
Jackson Felden - Cloud and Security
Рет қаралды 3,3 М.
Live response
20:48
Microsoft Security Community
Рет қаралды 2,2 М.
Windows Defender vs Ransomware 2024
7:17
PC Security Channel
Рет қаралды 92 М.
Always On VPN Deployment Guide
1:45:23
divv
Рет қаралды 81 М.
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН