Explore the process of building an effective security playbook within Security Onion in this conference talk from Security Onion Conference 2019. Learn how to integrate host data, manage sensitive shared resources, and import detections. Discover techniques for creating templates, executing queries, and pivoting through data. Gain insights into leveraging Elastic Search for enhanced security monitoring and response capabilities. Equip yourself with practical knowledge to construct a robust playbook tailored to your organization's security needs using Security Onion's powerful features.
Overview
Syllabus
Intro
Integration with host data
Sensitive shared resources
The PlayBook
Importing Detections
Templates
Query
Pivot
Elastic Search
Taught by
Security Onion