Learning Sysmon - Network Connection (Video 8)

preview_player
Показать описание
In this video, Research Team Lead Carlos Perez goes over how to build a baseline for the system so it is easier to stop outliers in the log for C2 connections, Lateral Movement and Data exfiltration.

Sysmon Modular:

Sysmon Community Guide:

PSGumshoe PowerShell Module

Sysmon Visual Studio Code Extension

Olaf Sysmon Modular video

00:00 Intro
01:58 Fields for the Event
03:12 Controlling Reverse DNS Lookup
04:00 Building a Baseline
10:14 Final Recommendations
Рекомендации по теме
Комментарии
Автор

very useful information, thx for uploading & sharing!!!!

monnombre
Автор

very nice method to simply pull all the regular events running on your machine 👍

SIEMEnjoyer