Investigating with Splunk - Tryhackme -

preview_player
Показать описание
Investigate anomalies using Splunk.

Рекомендации по теме
Комментарии
Автор

Great video! I appreciate the assist with backdoor user!!

upshawsm
Автор

Great video. Thank you! For the PowerShell logging event for the malicious execution "index=main powershell EventID=4103" can be used as well I guess.

Sesu-slvn