How To Network Forensics Cyberdefense VM

preview_player
Показать описание
This video I will be going over my new CyberDefense Vm I created for Network Forensics. This Virtual machine I created for the purpose of analyzing pcap files to determined what happened during and Incident Response involving a compromise Network.

The system components are:
- Elasticsearch
- Kibana
- Filebeat
- Kali Linux Defensive Tools Only
- Brimsecurity
- Tshark
- Wireshark

The system is build with Debian 11 and I have pre-built dashboards in kibana to display information about the pcap file that was ingested into elasticsearch This will give you the visual to see all the information that in captured over that Network that can aid in your investigation..
Рекомендации по теме
Комментарии
Автор

Thanks, but I am waiting for elastic 8.0 xdr deployment guide.

ankury