H & A Security Solutions
H & A Security Solutions
  • 35
  • 327 875
ReflexSOAR - Quickstart Installation
ReflexSOAR is an open-source event triage, investigation, and automation platform. It is designed by experts in the field to maximize SOC efficiency and orchestrate automation to abstract away mundane tasks. The result is streamlined efficiency and focuses on alerts or events that matter.
This video provides a walkthrough on how to quickly install ReflexSOAR. For more information as well as the installation command provided in this video, please visit the link below.
docs.reflexsoar.com/en/latest/getting-started/
Переглядів: 931

Відео

ReflexSOAR - CaseManagement
Переглядів 2982 роки тому
Case management involves the process of documenting and tracking your investigations. Good case management also includes the capability to provide guided walkthroughs, automatic creation or merging of data into cases, and more. This video is a quick tutorial on case management within ReflexSOAR. The solution shown in the video is: reflexsoar.com
ReflexSOAR - Automatic Correlation with Intel Lists
Переглядів 1842 роки тому
Intel lists are static or dynamic lists of content. They are useful for correlating and identifying known bad or malicious content such as URLs, hashes, etc. Intel lists are also helpful for automatic false positive reduction by correlating known benign or authorized use cases such as dismissing events caused by internal vulnerability scanners. The use cases are endless. Static intel lists are ...
ReflexSOAR - Automatic alert handling with Event Rules
Переглядів 2582 роки тому
Are you dealing with large amounts of events or alerts? Do you struggle to keep up? If so, ReflexSOAR event rules are a must. Event rules allow organizations to automatically take action against historical, current, and future events with automated logic. This video demonstrates how to use the Reflex Query Language (RQL) to match select events and take actions such as dismissing events with sel...
ReflexSOAR - Event Queue
Переглядів 2062 роки тому
When you triage events, it is critical that the interface is intuitive and fluid. In this video, the ReflexSOAR event queue is shown to reflect its ability to: - Provide an at-a-glance view of events and information for analyst consumption - Quickly filter in and out on information of interest - Ability to pivot to original data - Dismiss or merge/create a case based on one or more events - Cre...
ReflexSOAR - Deduplicating Alerts with Signature Fields
Переглядів 2652 роки тому
Organizations struggle enough to keep up with their day-to-day tasks let alone the numerous volume of alerts they need to monitor. One method to significantly help is to deduplicate events that are similar and correlate. In this video, we demonstrate how to configure Signature Fields to hand pick select fields so that if their values match the event gets rolled up into one event card. The solut...
ReflexSOAR - Inputs
Переглядів 6722 роки тому
Getting events into an event/alert console is simple and intuitive withe the use of ReflexSOAR inputs. This video walks through setting up a new input to retrieve Intrusion Detection System (IDS) alerts stored in Elasticsearch/OpenSearch into ReflexSOAR for alert triage and case management purposes. Inputs allow you to: - Consistently pull events into ReflexSOAR - Add Observable fields for hist...
Docker 101 - The Quick Basics
Переглядів 8232 роки тому
This live stream video focuses on learning how to deploy and use Docker. Emphasis is in place to quickly install Docker and then start deploying containers. The video covers: - Installing Docker via OS repository vs. Docker repository - Deploying containers with CLI or docker-compose or swarm stacks - How to handle storage with containers so you can delete and deploy containers at will - Bonus ...
Solving Alert Investigation and Triage Challenges through Open-Source Tooling
Переглядів 9492 роки тому
Welcome to our sneak peek into ReflexSOAR, an open-source tool with an emphasis on making alert triage and investigations wildly more efficient. Our discussion focuses on: - Difficulties in triaging large quantities of alerts - Challenges in identifying characteristics in alerts that need tuning - Areas of simple, yet efficient automation - How to structure triage vs investigations in regards t...
Windows Event Forwarding at Scale
Переглядів 16 тис.3 роки тому
This video shows how organizations can implement Windows Event Forwarding so that logs can be shipped from Windows endpoints to Windows Event Collectors. The video is a full walkthrough showing how to configure each component. In addition, it includes advanced topics such as the Windows Event Collector subscription registry keys and how to assign computers to multiple collectors dynamically. If...
Proxmox Install - The Best Free Hypervisor of 2021
Переглядів 36 тис.3 роки тому
Proxmox is an amazing hypervisor offering full functionality even in its free edition. This video covers multiple aspects of Proxmox: - Installation - Configuring free update repositories - Tuning system settings - Network configuration - Hyperconverged Storage
How to Get Hyper-V Up and Running
Переглядів 8933 роки тому
This video demonstrates how to get Microsoft Hyper-V up and running. This includes installation and configuration and includes setting up a multi-server failover cluster to migrate a virtual machine with storage from one host to another with it still running. If you are interested in learning more about Hyper-V and how to get it going, this video is for you. Don't forget to subscribe.
How to create a Windows Server install USB
Переглядів 4013 роки тому
Struggling with how to create a bootable Windows Server install USB? This video walks through an easy method of building a bootable Windows Server installation USB using Rufus. Rufus provides an easy-to-use GUI that simplifies USB creation compared to other methods that use command-line PowerShell.
vSphere, Hyper-V, and Proxmox - Which hypervisor is best?
Переглядів 20 тис.3 роки тому
This video contains a recorded discussion on which hypervisor is best for a home/business lab design. The focus of the conversation is on using vSphere, Hyper-V, and Proxmox to emulate an enterprise lab using a type 1 hypervisor. There also is a conversation around type 2 hypervisors like VMware Workstation and Oracle Virtualbox. Some topics that came up during the discussion: 1. What is a type...
Finding the Evil in Encrypted TLS Traffic with Machine Learning
Переглядів 8913 роки тому
This recorded webcast was a discussion on Bryan Scarbrough's SANS gold paper "Malware Detection in Encrypted TLS Traffic Through Machine Learning". The webinar focused on the below items. - How Bryan learned how to apply machine learning against TLS - How long it took Bryan to learn and apply his knowledge - How it is possible to find malicious use of encrypted communication In the recording, B...
Home Lab - vSphere and vCenter Installation and Configuration Guide
Переглядів 185 тис.3 роки тому
Home Lab - vSphere and vCenter Installation and Configuration Guide
Home Lab - Identify Your Motivation
Переглядів 1 тис.3 роки тому
Home Lab - Identify Your Motivation
Virtualization and Containers
Переглядів 1,3 тис.3 роки тому
Virtualization and Containers
Why a Home Lab and Hobby Farming
Переглядів 6903 роки тому
Why a Home Lab and Hobby Farming
Security Lab Hardware Recommendations in 2021
Переглядів 1,7 тис.3 роки тому
Security Lab Hardware Recommendations in 2021
MITRE DeTTECT - Data Source Visibility and Mapping
Переглядів 14 тис.3 роки тому
MITRE DeTTECT - Data Source Visibility and Mapping
Planning the Ultimate Home Lab: Live Stream Recording
Переглядів 1,7 тис.3 роки тому
Planning the Ultimate Home Lab: Live Stream Recording
Why Building an Enterprise Lab Matters
Переглядів 2,7 тис.3 роки тому
Why Building an Enterprise Lab Matters
Making Alerts Meaningful with Data Enrichment
Переглядів 5913 роки тому
Making Alerts Meaningful with Data Enrichment
Data Enrichment using Dynamical AD Info
Переглядів 2993 роки тому
Data Enrichment using Dynamical AD Info
Data Enrichment Using Ruby with Logstash
Переглядів 1,2 тис.3 роки тому
Data Enrichment Using Ruby with Logstash
Data Enrichment with GeoIP and Logstash in 60 seconds
Переглядів 1,9 тис.3 роки тому
Data Enrichment with GeoIP and Logstash in 60 seconds
Data Enrichment using Memcached - Instant Correlation
Переглядів 4633 роки тому
Data Enrichment using Memcached - Instant Correlation
Data Enrichment via HTTP Calls with Logstash
Переглядів 9293 роки тому
Data Enrichment via HTTP Calls with Logstash
Data Enrichment via File Lookups with Logstash
Переглядів 4363 роки тому
Data Enrichment via File Lookups with Logstash

КОМЕНТАРІ

  • @JoeConstance-i7h
    @JoeConstance-i7h 19 днів тому

    Lopez Susan Thompson Michael Rodriguez Angela

  • @JoeConstance-i7h
    @JoeConstance-i7h 22 дні тому

    Lee Gary Williams Timothy Martinez Margaret

  • @Dean-rs2nt
    @Dean-rs2nt Місяць тому

    Can you change the ip addreaa at the top in vCenter to a name instead ??

  • @alfaisalabdulkader8119
    @alfaisalabdulkader8119 Місяць тому

    The video was very informative and interesting, best ever video I have seen so far....Thanks so much.😊 Keep up the spirit.

  • @evand5271
    @evand5271 Місяць тому

    Thanks! One question: does WinRM and the associated WinRM firewall rules in Defender need to be enabled on all clients as well as the Windows Event Collector (WEC)? Specifically, you run "winrm quickconfig -quiet" & "Set-Service -Name WINRM -StartupType Automatic" on the collector during your first steps, but you do not mention that this needs to be compelted for all clients. Another tutorial has me enabling the service and firewall rules via a seperate WinRM Group Policy Object and applying this GPO to all domain comptuers. Without this extra step, I have been unable to get it to work. Maybe you mention this and I overlooked it, but it would be great to hear your input on this issue/topic. Thank you!

  • @ParabulaMan
    @ParabulaMan 2 місяці тому

    Fucking god

  • @FRITTY12348546
    @FRITTY12348546 2 місяці тому

    XFCE +1

  • @FRITTY12348546
    @FRITTY12348546 2 місяці тому

    Thank you so much for the content, seeing application is what helps me learn

    • @FRITTY12348546
      @FRITTY12348546 2 місяці тому

      One thought is how do you apply it one model matrix system? Windows servers, linux servers other OS or applications or overall one model

  • @davidnajeme8222
    @davidnajeme8222 2 місяці тому

    Rockstar... the best video on VMware intro guide on vSphere and vCenter

  • @ewangekang4960
    @ewangekang4960 3 місяці тому

    Great job Justin Please could you share a VMware online practice lab Thanks. I need to dirty my hands

  • @subhanullahasim721
    @subhanullahasim721 3 місяці тому

    Thank you.

  • @phogerman
    @phogerman 4 місяці тому

    That's a great video 👏

  • @ErLeuchten
    @ErLeuchten 4 місяці тому

    even tho 3 years old it is still the best english vmware setup introduction guide on youtube 👍thanks

  • @sofi6463
    @sofi6463 4 місяці тому

    This is awsome please continue from this

  • @MirzaArshadBeg-fu3qu
    @MirzaArshadBeg-fu3qu 4 місяці тому

    Thank You so much

  • @OkThanks999
    @OkThanks999 5 місяців тому

    Man, I cant thank you enough. This works. I followed 4-5 different tutorials but none of them worked. Really appreciate your work.

  • @MoSec9
    @MoSec9 5 місяців тому

    هذشي راه بزاف. اينهم المسؤولين المغاربة. بركة من هذا المهزلة تاع اليد الممدودة. الدولة والحكومة لهم مسؤؤلية الدفاع عن المواطنين والمصالح الوطنية. وابزاف هذشي. ماذا تنتظرون؟ تنتظرون العالم ان يأتي اليكم ليقول لكم فعلا الجزائر ظالمة. لا احد سيعير اهتماما لك اذا لم تطالب بحقط. اش هذ الزبل كاع تفو على بنادم موسخ بلانا به الله وهذ الحكام الخانعين المنونخين لي حاكمينا. الله يرحم الحسن الثاني هذشي لي كاين وصافي. اما ملي واحد البوال وسكيري بوخنونة دارو لنا هذ الحالة وباقين كنزقزقوا اليد الممدودة فراه هزلت

  • @damienkubik1380
    @damienkubik1380 5 місяців тому

    Awesome video! Very informative and detailed. Helped me out a lot

  • @gabid3962
    @gabid3962 6 місяців тому

    you lost me when you started configuring the network stuff..

  • @furkandemirel8014
    @furkandemirel8014 7 місяців тому

    Hello! Im not sure if you are still responding to comments but i have a question :( Video cleared lot of things for me, but I didn't understand the part with the group policy. Should I create a seperate Group policy for each WEC? Or shoud I just add other WECs to "subscription manager string"?

  • @harshnasit6021
    @harshnasit6021 7 місяців тому

    MASTERPIECE! 💯👌

  • @FlimFlamBougelets
    @FlimFlamBougelets 8 місяців тому

    Could this tool take a threat model --- and map to Mitre controls?

  • @linuxlove1912
    @linuxlove1912 8 місяців тому

    Thanks

  • @tobypass108
    @tobypass108 9 місяців тому

    Love this video. I was able to follow along. Rather than just using your repo, I downloaded it with git then coped the relevant functions and log files from es.py into my script so I could see how it worked. Really good walkthrough - appreciate the knowledge sharing. Thank you.

  • @pismed2495
    @pismed2495 9 місяців тому

    can you help me i will connect to elastic cloud with file python

  • @millschristophe9865
    @millschristophe9865 9 місяців тому

    What book would you recommend to learn VMware vSphere, ESXi ?? Ty

  • @melimelon8
    @melimelon8 9 місяців тому

    what a great video. Thank you so much for providing informative videos that are interesting and easy to understand! New subscriber!

  • @bobkoss280
    @bobkoss280 9 місяців тому

    404 on excel link

  • @bobkoss280
    @bobkoss280 9 місяців тому

    If this were deployed, how would you handle backups?

  • @dougramsey6697
    @dougramsey6697 10 місяців тому

    Great! one question, does the configuration stay the same for windows 2022 Server?

  • @tsaba2319
    @tsaba2319 10 місяців тому

    Great

  • @michaelwaterman3553
    @michaelwaterman3553 10 місяців тому

    This is so cool, thanks! I've got it working with your video and now I can do a write-up for my org.

  • @bobkoss280
    @bobkoss280 10 місяців тому

    Awesome video!

  • @khosrowjalali7898
    @khosrowjalali7898 10 місяців тому

    That was a really walkthrough Home Lab, This really helped me set up my own VCP home Lab and practice. Thank you!

  • @DanielColl-z6o
    @DanielColl-z6o 11 місяців тому

    Im using Windows Server 2022, Member servers are not reporting to the Collector. Are there different commands to run and does the GPO need different settings?

  • @FuzNuts
    @FuzNuts 11 місяців тому

    The only issue I had was when I put in the subscription manager, I used domain.local:5985/wsman/SubscriptionManager/WEC,Refresh=120 <- Here I accidently put a period instead of a coma. Once I fixed this issue. The issue was resolved. Great Video! Subscribed for more great content.

  • @NSPK-
    @NSPK- Рік тому

    Good understanding

  • @NSPK-
    @NSPK- Рік тому

    🎁

  • @NSPK-
    @NSPK- Рік тому

    Very good knowledgeable video! Really appreciate for very excellent VMware networking. understanding

  • @dimabashynskyi4984
    @dimabashynskyi4984 Рік тому

    Great walkthrough =) thanks =)

  • @Jerome.Powell.Official
    @Jerome.Powell.Official Рік тому

    Superb

  • @sfarovski-michelfaro4420
    @sfarovski-michelfaro4420 Рік тому

    Hi. I'm trying to convert the file YAML to JSON. It gives me an error. KeyError: 'PRE'. Now I used and online YAML-->JSON converter, but then ATTACK Navigator says; WARNING: Uploaded layer version (1.2) does not match Navigator's layer version (4.4). The layer configuration may not be fully restored. When I click continue, I get the empty Matrix and no colouring or values. Is someone that could help me with this?

  • @exit3119
    @exit3119 Рік тому

    Thank you for the excellent explanation, I'm really looking forward to your videos about the distributed switch

  • @mauriciozp84
    @mauriciozp84 Рік тому

    Thanks for taking the time and answering our concerns!! I am trying to learn a little bit about this framework, am wondering how would you map an EDR, which is a blackbox, like Falcon from Crowdstrike? Or which will be your approach, thanks man.

  • @mauriciozp84
    @mauriciozp84 Рік тому

    Thanks for the awesome explanation!! Quick question, around minute 4:00 you uploaded to the Navigator the JSON file of Sysmon, from where that file came from? Was that file generated by DeTTECT? How? That file clearly had more coverage than regular Windows logs, but am wondering how that mapping was done, thanks.

    • @HASecuritySolutions
      @HASecuritySolutions Рік тому

      That file was created from using DeTTECT. I created a data source file stating I have built-in Windows channels, Sysinternals Sysmon coverage, and other Windows channels that there are common community rulesets such as from Sigma Generic Signatures. I then used the DeTTECT command-line script to convert it to a navigator JSON layer that I could upload to MITRE Navigator.

    • @mauriciozp84
      @mauriciozp84 Рік тому

      @@HASecuritySolutions Probably didn't explain myself right, but I was wondering how the YAML was created (the coverage), please correct me if I am wrong but if we want to include Sysmon as a data source in DeTTECT or any other data source we MUST go to the vendor documentation and manually identify which techniques they provide some coverage according to their capabilities and use that intel in DeTTECT, right? I was under the impression that maybe there is a repository with the most common data sources already mapped, it sounds more like a community project as there are so many data sources out there (just thinking out loud here sorry)

    • @HASecuritySolutions
      @HASecuritySolutions Рік тому

      @@mauriciozp84 I think I understand your question now. For this, I did go to learn.microsoft.com/en-us/sysinternals/downloads/sysmon to look at all the event IDs generated and what they are for. Then, I map those to the corresponding MITRE Data sources which is what DeTTECT's data source list is based on (attack.mitre.org/datasources/). That builds the initial YAML file. To my knowledge, there is not a pre-provided list of software to data sources that you can use to build the YAML. However, while there are a ton of attack techniques in MITRE, there's currently only about 50 data sources. So doing the data source mapping does not take that long. For example, I can compare visibility from Sysmon vs an EDR's telemetry logs in about an hour just by mapping what logs I'm provided access to within MITRE Data Sources (within DeTTECT)

    • @mauriciozp84
      @mauriciozp84 Рік тому

      @@HASecuritySolutions Got it, I was afraid you will say it was a manual work XD, thanks for the time you took answering our concerns, great video man!!

  • @ITskintechpharmagroup
    @ITskintechpharmagroup Рік тому

    question: i have running for long time vmware esxi 6.7 pre installed in DELL EMC , which i wish to put it into a vmware center to control it and, i've just recently buyed another poweredge640 dell EMC whic also has vmware esxi7.0 . Can i create or download a vcenter to control both vmwares? thsnks thoug

  • @AshBlitz
    @AshBlitz Рік тому

    Thanks. It is extremely beneficial

  • @user-qr4jf4tv2x
    @user-qr4jf4tv2x Рік тому

    i like the points of dumbing down your resume for dumb employers

  • @user-qr4jf4tv2x
    @user-qr4jf4tv2x Рік тому

    looks like i'm going for proxmos.. i do hope proxmos becomes more popular in enterprise

  • @treasajoshy9232
    @treasajoshy9232 Рік тому

    Really good 👍