Security Onion Essentials 2024 Intro to Analyst Tools

Поділитися
Вставка
  • Опубліковано 31 гру 2024

КОМЕНТАРІ • 12

  • @callmebigpapa
    @callmebigpapa 4 місяці тому +1

    Thank you so much this is great. You are a gifted teacher.

  • @L3af0553
    @L3af0553 4 місяці тому +2

    I have watched the install videos and you installed the eval version, i plan on installing the desktop version and am wondering if i will still need to use the web interface to monitor traffic

    • @security-onion
      @security-onion  4 місяці тому +2

      You will need some kind of web browser whether its inside the Security Onion Desktop or on some other machine. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!

  • @fatushcorner
    @fatushcorner 5 місяців тому

    Thank u ☺️

  • @nico3006
    @nico3006 Місяць тому

    is it okay if i install to a external SSD?

    • @security-onion
      @security-onion  Місяць тому

      You can try it, but we do not recommend or support it.
      If you have further questions or problems, please start a new discussion at securityonion.net/discuss

  • @TheSoliver84
    @TheSoliver84 4 місяці тому

    Are there real alarms in the evaluation or are the placeholders not real?

    • @security-onion
      @security-onion  4 місяці тому

      The alerts are real. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!

    • @TheSoliver84
      @TheSoliver84 4 місяці тому

      @@security-onion OK, how do I find the corresponding computers or devices? Only IP addresses are displayed but no MAC addresses.

    • @security-onion
      @security-onion  4 місяці тому +1

      You may be able to find MAC addresses by pivoting to PCAP and then opening that PCAP in Wireshark or some other PCAP utility. However, depending on how you're monitoring traffic, the MAC addresses shown may not actually be the MAC addresses of the actual endpoints. For this reason, most folks focus on IP addresses rather than MAC addresses. Depending on your network, you may be able to correlate an IP address to an actual device via DNS, DHCP, or other means. If you have further questions or problems, plese start a new discussion at securityonion.com/discuss rather than replying here on UA-cam. Thanks!