Completed
Tools and Procedures
Class Central Classrooms beta
YouTube videos curated by Class Central.
Classroom Contents
SOC Automation - Enterprise Blueprinting and Hunting Using Open-Source Tools
Automatically move to the next video in the Classroom when playback concludes
- 1 RSAConference 2019 San Francisco March 4-8 Moscone Center
- 2 Know Your Environment
- 3 "Blueprinting" Methods Reactive • Firehose
- 4 Tools and Procedures
- 5 Intro to OsQuery
- 6 Pros/Cons
- 7 Low Prevalence Executables
- 8 Leveraging OsQuery
- 9 Getting ARP data from OsQuery
- 10 Automation Overview
- 11 Where do you put your data?
- 12 Data Collection
- 13 Data Storage
- 14 Querying Data
- 15 Docker
- 16 Filebeat
- 17 Next Steps
- 18 Using Statistical Analysis for Threat Hunting
- 19 Analyzing Data
- 20 Hunting Methodologies
- 21 Mac Addresses - Uncommon Environmental OUIS
- 22 Prevalence of Executables
- 23 Filtering Data
- 24 Mass Searching
- 25 A Story of Two Executables (PLink)