SOF ELK® A Free, Scalable Analysis Platform for Forensic, Incident Response, and Security Operation

Поділитися
Вставка
  • Опубліковано 15 вер 2024

КОМЕНТАРІ • 16

  • @sekarov
    @sekarov 11 місяців тому +1

    Do this SOFELK have parser to parse windows and Linux log fields. The provided ELK in FOR508 dosent have parser to parse windows logs, so I find very difficult to pivot the logs for investigation.

  • @arsalananwar8265
    @arsalananwar8265 2 роки тому +1

    wow

  • @francescofaenzi7095
    @francescofaenzi7095 3 роки тому

    Any experience integrating SOF-ELF with SIGMA rules?

  • @stelluspereira
    @stelluspereira 4 роки тому +1

    is there way to get the large set of logs downloadable from your web portal (which you mentioned that you have during the talk, size 500GB ?)

    • @fleetr06
      @fleetr06 4 роки тому

      Do you have them available to people? I have them already on 3 jump drives, but only because I went to the Bootcamp.

    • @stelluspereira
      @stelluspereira 4 роки тому

      Dear fleetr06 ,
      Is there a way to share(if it is ok with the trainer)

    • @fleetr06
      @fleetr06 4 роки тому

      @@stelluspereira I don't have a way to host them, but if I was you I would reach out to SANs. They are pretty cool.

    • @stelluspereira
      @stelluspereira 4 роки тому

      fleetr06 , Thankyou Sir
      I am not sure how to reach them

    • @stelluspereira
      @stelluspereira 4 роки тому

      @@fleetr06 , i can send you an usb drive, what would best way to contact you