-
-
-
No, Windows and Sysmon, not Syslog https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon … And AV ist still the most important.
- Još 2 druga odgovora
Novi razgovor -
-
-
Also more enterprises critical assets are UNIX than Windows?
-
Just because you treasure chamber is the most valuable chamber in your castle doesn't mean that you should place your detection there and not in the chamber that holds your guards' armor and helmets.
- Još 5 drugih odgovora
Novi razgovor -
-
-
Auditbeat for Linux auditd is what Sysmon is for Windows events. You can deploy it to every system and get socket logs and process logs. It even has the connection-id from
@corelight_inc so you can easily correlate the host network connection to@Zeekurity and@Suricata_IDS -
Now that‘s interesting
Kraj razgovora
Novi razgovor -
-
-
Hello, would you mind elaborate the reasons AV is the most important for you? For a lot of ppl, it just means quarantine and blocking business, logs tends to be very noisy and with less value compared to sysmon for ex
-
Most threats leave traces in AV logs but orgs usually handle the AV logs in a wrong way. You can use my "Antivirus Log Analysis Cheat Sheet" for a better, more purposeful processing of AV log data.https://www.nextron-systems.com/2019/10/04/antivirus-event-analysis-cheat-sheet-v1-7-2/ …
- Još 1 odgovor
Novi razgovor -
-
-
Anyone know of any good guides to firewall logging. End up logging everything, with multiple sites vpn connected the log is insane vs any other log. My inclination would be internet inbound/outbound and traffic to servers in/out.
-
@pedantic_hacker I consider outgoing blocked as most important and would drop incoming blocked, as it is just the white noise of the Internetpic.twitter.com/zE867EiXuo
- Još 1 odgovor
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.