Slides from my @RSAConference session "Tracking Hackers on Your Network with Sysinternals Sysmon" https://onedrive.live.com/redir?resid=D026B4699190F1E6!2575&authkey=!AGFBok7JLkOZSgE&ithint=file%2cpptx …
-
-
Replying to @markrussinovich
@markrussinovich Thanks for#Sysmon & RSA slides! Getting ready for hunting :) Logs from ~10K hosts (target: 25K)pic.twitter.com/YePlLlqM1N
5 replies 15 retweets 35 likes -
Replying to @c_APT_ure
@c_APT_ure@markrussinovich What's your current setup like Tom? Cheers!1 reply 0 retweets 1 like -
Replying to @bartblaze
@bartblaze Sysmon and Splunk Universal Forwarder on endpoints with configs each. Or what were you asking? /cc@markrussinovich1 reply 0 retweets 0 likes -
Replying to @c_APT_ure
@c_APT_ure Was wondering about your hardware & sofware ie. what are you running it on :)1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze I'm not in charge of Splunk deployment sizing, architecture or ops. There are better ppl than me to discuss this...2 replies 0 retweets 0 likes
Replying to @c_APT_ure
@c_APT_ure No worries. Thanks for your reply!
2:50 PM - 29 Apr 2016
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.