Threat Hunting with Network Flow - SANS Threat Hunting Summit 2017

Поділитися
Вставка
  • Опубліковано 25 гру 2024

КОМЕНТАРІ • 8

  • @shanecherniss
    @shanecherniss 4 роки тому +5

    Nice presentation on beginning to understand the concept of Netflow. It failed to deliver on the content in the description:
    The focus of this presentation will be on how to incorporate network flow analysis into your threat hunting toolkit. We will cover topics such as anomaly discovery versus signature matching, IP expansion, longitudinal analysis of threat actors, how network flow relates to the Cyber Kill Chain, and where network flow analysis should sit in the threat hunting cycle. We will look at real world examples of the effects of these techniques in discovering malicious actors on networks.

  • @suknow2008
    @suknow2008 4 роки тому +1

    This is really well done in terms of explaining flow for hunting

  • @Ben_79
    @Ben_79 3 роки тому

    I hope I can watch/listen to it later but I'll have to deal with the echoing ring. This is not against the presenter but the audio could have been better.

  • @AlainaD2003
    @AlainaD2003 5 років тому +1

    Great presentation.

  • @osmaster3327
    @osmaster3327 4 роки тому

    Great.Thank you.

  • @ankury4762
    @ankury4762 2 роки тому

    Cool

  • @adamwarowny4836
    @adamwarowny4836 3 роки тому +1

    Same shit as everywhere. Same diagams, same nothing-giving examples.