What is Sysmon ¦ How to Install and Set Up Sysmon
>> YOUR LINK HERE: ___ http://youtube.com/watch?v=PY1v_mZnjks
This is a Short video about Sysmon .It is a very good SysInternals tool and has been widely used these days in threat hunting .It Provides very good information about different process creations along with their command line Parameter . • Installation of tool is simple but without a good configuration ,it will not provide you enough data . • This is First Part of the video . In the next part , we will show you on how to collect logs via Splunk. • These Links are used in making this video . • Download Sysmon and Sample Configuration • ================================== • 1. https://docs.microsoft.com/en-us/sysi... • 2. https://github.com/olafhartong/sysmon... OR • 3. https://github.com/SwiftOnSecurity/sy... • Installation of Sysmon with Configuration • ================================== • sysmon -accepteula -i sysmonconfig.xml • Generate Logs via Atomic red team • ============================= • https://redcanary.com/getting-started... • Speaker's Profile • =============== • This Session is done by Shahzad Subhani .He is an information security enthusiast with 20 years of experience in different cyber security domains. His core expertise includes Malware Protection, Ant phishing, Email Security, Data Loss Protection, Encryption, Incident management, Digital forensics and SIEM Solutions. He is a hands-on guy and is always keen to mentor and share knowledge with his colleagues and juniors. He also writes Security articles as well as create videos on different information security topics. • Shahzad Subhani is also founder of GISPP (Global Information Security Society for Professionals of Pakistan) which has now members from 18 different countries. GISPP platform has brought many Pakistani Information security professionals together in order to share knowledge as well as to support each other professionally. • You can read More articles from Shahzad Subhani at this link . • https://www.gispp.org/user/shahzad-su... • About GISPP • =========== • It is an effort by GISPP (Global Information Security Society for Professionals of Pakistan) .GISPP was initiated in 2016 by a group of Pakistani Information Security professionals living and working in Saudi Arabia. You can follow us on our social media links mentioned on our Channel Page . • #Sysmon #SysInternals #Threathunting #SwiftOnSecurity #GISPP #GisppAcademy #GisppTraining #Cybersecurity #Informationsecurity
#############################
