Sigma - Generic Signatures for Log Events

Sigma - Generic Signatures for Log Events

Cooper via YouTube Direct link

Rule Example: Webshell Reconnaissance Activity

8 of 18

8 of 18

Rule Example: Webshell Reconnaissance Activity

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Sigma - Generic Signatures for Log Events

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Log Monitoring
  3. 3 Problems!
  4. 4 It's open source!
  5. 5 Rule Format
  6. 6 Rule Example: Mimikatz Detection
  7. 7 WCE Detection
  8. 8 Rule Example: Webshell Reconnaissance Activity
  9. 9 Rule Example: Relevant AV Events
  10. 10 Rule Example: Suspicious Login Attempts
  11. 11 Example: Django Exceptions
  12. 12 Challenges in Rule Conversion
  13. 13 Sigma Converter Configurations
  14. 14 Conversion Process
  15. 15 Backend Implementation: Splunk
  16. 16 Contributors and Community
  17. 17 Current State and Future Work
  18. 18 Questions?

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.