Threat Hunting: Foothold - TryHackMe WalkThrough
Автор: TryHackMe Walkthroughs
Загружено: 2023-10-24
Просмотров: 1652
Описание:
Introduction:- Using ELK stack by Elastic (which is core technology of many SIEM solutions), hunting suspicious activities indicating initial user or host compromise.
#threathunting #malwareHunting #EnterpriseThreatHunting #sysmon #logHunting #cyberThreatHunting
Chapters
0:00 - Threat Hunting with ELK - Intro
3:37 - Attacker's Initial Access Hunting
17:00 - Payload Execution - Log Hunt
29:40 - Defense Evasion Logs by Hacker
34:02 - Malware Persistence Logs
38:12 - Command & Control (C2) Log Hunting
Topics Covered:-
Attacker Initial Access
Payload Execution
Malware Defense Evasion
Persistence of malware
Command and Control of hacker
Room Link:-
https://tryhackme.com/room/threathunt...
References:-
https://learn.microsoft.com/en-us/sys...
https://en.wikipedia.org/wiki/Cyber_t...
https://github.com/olafhartong/sysmon...
https://www.elastic.co/elastic-stack
https://elastic.co/beats
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: