Windows Event Forwarding and Event Collectors In-Depth

  Рет қаралды 12,157

SANS Cyber Defense

SANS Cyber Defense

Күн бұрын

Пікірлер: 10
@unatommer
@unatommer Ай бұрын
This was great, it pointed me in the right direction.
@chuck_henry
@chuck_henry 2 ай бұрын
Will you publish the event filters you recommend somewhere?
@zikkthegreat
@zikkthegreat 2 жыл бұрын
is there a link for the followup video on implementing?
@golgothus
@golgothus 3 жыл бұрын
Absolutely loved this webcast! Plenty of useful information in regards to the benefits of WEF/WEC usage, especially in an environment where you have multiple SIEMS. Also, Powershell was mentioned, definitely seems like wecutil will be worth looking into further for automation and scripting purposes!
@peterparker175
@peterparker175 Жыл бұрын
does anyone have manual how to setup WEC cluster with 2 or 3 servers?
@chamkadar86
@chamkadar86 2 жыл бұрын
Can some one please make video on how to configure WEC for workgroup environment with CA server.
@daledreher4107
@daledreher4107 2 жыл бұрын
Awesome video, very helpful! Justin has the same handwriting as me 😊
@avtraveller
@avtraveller 2 жыл бұрын
I did similar deployment in our enviroment but WEC is a single point of failure . We tried the windows built in mechanism with 2 virtual servers configured as cluster but didnt work , Any ideas how to mitigate this ?
@simple-security
@simple-security 2 жыл бұрын
summary: don't use wec/wef, stick to ARC/AMA agent for servers? and log analytics agent for workstations if needed (AMS not supported for workstations)? with advanced powershell auditing enabled in group policy? plus edr agent for advanced threat detections?
@BarryHarrellYouTube
@BarryHarrellYouTube Жыл бұрын
Waste of time. The one guy on the right has a video on this subject and none of his links work. You think that if he teaches he would make sure his links work. But nope - wasted my time.
Windows Event Forwarding at Scale
33:02
H & A Security Solutions
Рет қаралды 17 М.
Detecting Command and Control Frameworks via Sysmon and Windows Event Logging
28:07
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 18 МЛН
When Cucumbers Meet PVC Pipe The Results Are Wild! 🤭
00:44
Crafty Buddy
Рет қаралды 63 МЛН
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 99 МЛН
Free Security Tools Everyone Should Use
13:15
The PC Security Channel
Рет қаралды 1 МЛН
BHIS | Intro to Windows Event Collecting | Nick & Noah | 1 Hour
57:22
Black Hills Information Security
Рет қаралды 6 М.
The Event Viewer, Explained (It's a mess)
10:21
Ask Leo!
Рет қаралды 21 М.
Building a Cybersecurity Program From the Ground Up
35:21
SANS Institute
Рет қаралды 10 М.
15 BIGGEST Data Centers on Earth
29:23
Top Fives
Рет қаралды 408 М.
Next Gen SOC
29:13
SANS Cyber Defense
Рет қаралды 1,1 М.
Expert OSINT Tools: Free, Powerful Bookmarklets for Digital Investigators
57:06
My OSINT Training - Your Home For OSINT Learning™
Рет қаралды 6 М.
Understanding the Windows Server Event Log
13:43
ITOpsTalk
Рет қаралды 8 М.
The Impact of AI with OSINT
35:29
SANS Cyber Defense
Рет қаралды 2,7 М.