Главная
Study mode:
on
1
Intro
2
Overview
3
Introducing Peter
4
Why we are here
5
Who has a SIEM
6
Assumptions
7
Methodology
8
Use Case Criteria
9
Top 10 Use Case 1
10
Top 10 Use Case 2
11
User Password Spraying
12
Antivirus Virus Detected
13
Windows Workstation Communication
14
User Added to Domain Administrator Group
15
New Service Account Creation Registration
16
Service Account Performing NonService Account Actions
17
NetFlow
18
Honorable Mentions
19
Recommendations
20
Download Presentation
21
Contact Information
22
How does an organization collect work station logs
23
Identify which websites should users in general
24
Baseline server traffic
25
Threat intelligence lists
26
How to get your MSSP to do these things
27
Get better and better at it
28
They dont know your environment
29
Vendor specifics
30
Encrypted update uploads
Description:
Explore a comprehensive conference talk on leveraging SIEM (Security Information and Event Management) systems to detect and prevent penetration testing activities. Learn about the top 10 use cases for SIEM, including user password spraying, antivirus detection, Windows workstation communication, and domain administrator group changes. Discover methodologies for implementing effective use cases, criteria for selection, and honorable mentions. Gain insights into collecting workstation logs, baselining server traffic, and utilizing threat intelligence lists. Understand how to optimize your MSSP (Managed Security Service Provider) relationship and continuously improve your security posture. Delve into vendor-specific considerations and encrypted update uploads to enhance your organization's cybersecurity defenses.

To Catch a Penetration Tester - Top SIEM Use Cases

Add to list
0:00 / 0:00