Тёмный

Cybersecurity SOAR EDR Project | Part 5 

MyDFIR
Подписаться 42 тыс.
Просмотров 2,5 тыс.
50% 1

Опубликовано:

 

23 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 79   
@Cyber.Panda.
@Cyber.Panda. 3 месяца назад
43 minutes of gold!! Thank you cyber guru!!🔥🔥
@MyDFIR
@MyDFIR 3 месяца назад
My pleasure!! Enjoy ❤️
@georgekenneth5305
@georgekenneth5305 3 месяца назад
Let your reward to mankind come from different places. Thanks for what you do
@MyDFIR
@MyDFIR 3 месяца назад
My pleasure! Thank you for watching ❤️
@sahilpc2727
@sahilpc2727 2 месяца назад
Just completed the whole project now gonna add it to my github with SS thanks to u my man
@MyDFIR
@MyDFIR 2 месяца назад
Beautiful! Great work
@maunton
@maunton 2 месяца назад
This SOAR EDR project was incredible! Following along and learning from your detailed explanations was so valuable and fun! Your insights into integrating and automating security operations have been incredibly enlightening. Thanks for sharing your expertise! I look forward to the next Awesome project that you present.
@MyDFIR
@MyDFIR 2 месяца назад
Thats great to hear! Thanks for participating ❤️
@NImuslimguy
@NImuslimguy 3 месяца назад
This tutorial was truly amazing. Learnt a lot and followed the steps as per your instruction. Didn't run into any errors. You are amazing mate. Keep up the great work. One day I hope to sign up for your course to thank you and check your other projects out. :)
@MyDFIR
@MyDFIR 3 месяца назад
Great to hear! Thanks for participating ❤️
@davidtosh5704
@davidtosh5704 3 месяца назад
Please more of such on field projects. Thanks once again big man
@MyDFIR
@MyDFIR 3 месяца назад
I do have some other projects on my channel - Feel free to participate and share them with me on LinkedIn! I would love to see your work!!
@jiblex256
@jiblex256 Месяц назад
For anyone wondering how to include the user prompt in the slack and or email: The way I found was to generate a dynamic link which can be included in either slack or email messages as a variable "PAGE.page_name", so in this case it would be "PAGE.user_prompt". Make sure that the page is downstream of the slack and email blocks, i.e. slack and email blocks connect downward to the page, just like in MyDFIR's example.
@MyDFIR
@MyDFIR Месяц назад
Beautiful!!! Great job on that 💙
@SamAndraly
@SamAndraly Месяц назад
@jiblex256 Thanks, now I am able to send a dynamic link to both email and slack.
@taherjhabuawala3675
@taherjhabuawala3675 29 дней назад
could you please share more details
@davidtosh5704
@davidtosh5704 3 месяца назад
Thank you for this priceless project Steven. From the intro to the end, it's fire. I will recommend this to others who are interested. God bless you my friend.
@MyDFIR
@MyDFIR 3 месяца назад
Much appreciated! The goal is to help those wanting to get practical experience and build up their portfolio. By you helping me share the content around, it would definitely help towards my goal.
@mbg_varshin2191
@mbg_varshin2191 7 дней назад
Hey steven, How can I integrate this directly to my web page which asks user prompt to isolate the machine or not? And then based on my response the action can be performed?
@John-w2i
@John-w2i 3 месяца назад
Great project, just finished it!
@MyDFIR
@MyDFIR 3 месяца назад
Awesome!!
@madhurhase8333
@madhurhase8333 3 месяца назад
W Content , W Labs & W Instructor
@MyDFIR
@MyDFIR 3 месяца назад
Thank you ❤️❤️
@ucheemmanuel8466
@ucheemmanuel8466 3 месяца назад
This is great!
@MyDFIR
@MyDFIR 3 месяца назад
Thank you!
@rsleepy255
@rsleepy255 2 месяца назад
I had an easier time with this Tines than I did with Shuffle. Will definitely keep Tines in mind moving forward
@MyDFIR
@MyDFIR 2 месяца назад
Awesome! I absolutely love tines😀
@ankyk3436
@ankyk3436 3 месяца назад
@MyDFIR The kind of content you output hatsoff bro, this is truly groundbreaking...❤❤
@MyDFIR
@MyDFIR 3 месяца назад
Thank you for the kind words ❤️
@URNEXTCISO
@URNEXTCISO 3 месяца назад
Thank you ❤
@anjalimaharaj4536
@anjalimaharaj4536 2 месяца назад
thank you very much for walking through this project, it has been a really great learning experience, I have a question, I used a VM instead of a cloud server for the endpoint and found that there were two instances installed with sensors and the isolation was stuck in waiting status, can you please explain if this is the expected behavior when using a VM as the endpoint?
@MyDFIR
@MyDFIR 2 месяца назад
That is unexpected behavior…try restarting the limacharlie service and see what happens!
@zaire-ida9316
@zaire-ida9316 3 месяца назад
Thank you for this! Can you please use Azure as the cloud next time?
@MyDFIR
@MyDFIR 3 месяца назад
Absolutely! I plan on doing something pretty cool with Azure :)
@zaire-ida9316
@zaire-ida9316 3 месяца назад
@MyDFIR Awesome! I'm looking forward to it.
@joshgo2888
@joshgo2888 3 месяца назад
Hello Maestro, based on your experience working with organizations, how much time do you spend working with these tools and how many alerts/rules are you guys making per day? also, do you use mitre att&ck to generate those rules?
@MyDFIR
@MyDFIR 2 месяца назад
It depends on the organization and how “mature” they are. We wouldn’t be making new alerts everyday instead it would be tuning existing ones and yes the mitre attack is a good guideline to follow but the goal isn’t to detect every single technique.
@morobbykleins1349
@morobbykleins1349 3 месяца назад
🙏🏽🙏🏽Thanks for your help 🫶🏾🫶🏾
@MyDFIR
@MyDFIR 3 месяца назад
Thank you for watching ❤️
@sanjo3108
@sanjo3108 3 месяца назад
The project is very clear and intuitive. Thank you so much. I have a small suggestion, would that be easy if we send the link to isolate the machine to email and directly isolate the machine by clicking that link?
@MyDFIR
@MyDFIR 3 месяца назад
Yup that is something you can do. 👍
@karthick7
@karthick7 Месяц назад
@@sanjo3108 do u know to send the user prompt link to user
@alyx3135
@alyx3135 3 месяца назад
Hi, can you please provide more details on the SOC analyst roadmap looking to buy it but you have YT vid about it thankss!
@MyDFIR
@MyDFIR 3 месяца назад
Yeah, the roadmap PDF contains links and resources where the video does not. You can watch the video for free and use that as a guide. No need to purchase the roadmap, unless you want to buy me a coffee haha 😁
@mehulsharma2140
@mehulsharma2140 3 месяца назад
Hey! steven, I've one question related to this Lazagne app. We created the rule and automation for this LaZagne app but what if any other app similar to this is run on the machine, This automation will work and show us the user prompt to isolate the machine or we have to configure the hashes and all those things manually first?
@MyDFIR
@MyDFIR 3 месяца назад
Depends on what available detections exist for LC, if none for that particular app, then you’ll need to configure it
@mehulsharma2140
@mehulsharma2140 3 месяца назад
@@MyDFIR okay...
@aviwemusa6109
@aviwemusa6109 3 месяца назад
Can you please do Wazuh multi-site implementation that helps organizations unify their security monitoring capabilities across multiple geographically dispersed locations or sites with single dashboard tutorial?
@MyDFIR
@MyDFIR 3 месяца назад
Sounds like a professional service job haha multi-tenancy might be a bit difficult due to the nature of being multi-tenancy. But something ill think about
@taherjhabuawala3675
@taherjhabuawala3675 29 дней назад
just a quick question everytime i run LaZagne it runs 6 times... 6 slack messages and 6 emails everytime what should i do?
@taherjhabuawala3675
@taherjhabuawala3675 29 дней назад
just this question sir rest everything worked perfectly fine
@abhinavakaranth3813
@abhinavakaranth3813 2 месяца назад
Are tools/platform used in this project free to use?
@MyDFIR
@MyDFIR 2 месяца назад
Free to use
@evanj51
@evanj51 2 месяца назад
So, how do we get it to go through all of the steps in tines without manually doing it. Like after its set up if you go run the lazagne program, is it suppose to automatically send you a message and an email and ask you to isolate?
@MyDFIR
@MyDFIR 2 месяца назад
Once all the steps are completed it should work automatically. Tines will send a slack message and email providing you with the alert information. Afterwards, you’ll go into tines and isolate if you choose to do so.
@evanj51
@evanj51 2 месяца назад
@@MyDFIR I tried and it didn’t work. I’ll have to do some troubleshooting. Thanks for the project btw! I created a documentation for it as well.
@evanj51
@evanj51 2 месяца назад
@@MyDFIR So I'm not sure what happened, but I looked back through my documentation and remembered where I connected LimaCharlie to Tines. I recopied the webhook url and put it in LimaCharlie again and now its working properly! When I run the command on my vm it sends me a message in slack and an email!
@MyDFIR
@MyDFIR 2 месяца назад
Awesome!!! Happy to hear that. Great job 🙌
@karthick7
@karthick7 Месяц назад
Hello, i have installed lima Charlie in my Another laptop and i have set a rule . When the process is running how can we SEND THE USER PROMPT to them for choosing yes or no
@MyDFIR
@MyDFIR Месяц назад
Honestly I am not sure how to send the user prompt from tines to lets say… via email. If you find out, let me know!
@karthick7
@karthick7 Месяц назад
@@MyDFIR I try to find out and let me know if u find 😇😇
@karthick7
@karthick7 Месяц назад
@@MyDFIR sir i really tried my best to find how to send the user prompt to user to choose yes or no but still i cant find the way to send the prompt pls help me sir 😢😢🥲🥲
@karthick7
@karthick7 Месяц назад
@@MyDFIR the solution i need is once the webhook detects how can we send the user prompt to the owner of the machine to select for isolation
@karthick7
@karthick7 Месяц назад
@@MyDFIR dont ignore my message pls < once when ur free pls reply me
@sundep-nl8pm
@sundep-nl8pm 3 месяца назад
kindly provide DFIR course related videos . i am into grc and now trying to switch digital forensics & incident response . kindly assist how to start and proceed🎉
@MyDFIR
@MyDFIR 3 месяца назад
Will be adding that in the future 👍
@mehulsharma2140
@mehulsharma2140 3 месяца назад
My man....This is Awesome. I want to know can we get that User Prompt message in our E-mail or Slack?
@MyDFIR
@MyDFIR 3 месяца назад
Thats a good question and one that I do not have an answer to 😂 if you find out, let me know!
@mehulsharma2140
@mehulsharma2140 3 месяца назад
Sure... I'll do some research work!
@mreo4107
@mreo4107 3 месяца назад
you forgot to add this on Playlist
@MyDFIR
@MyDFIR 3 месяца назад
You’re correct, ill add this to the playlist. Thank you!
@ruchitpatel961
@ruchitpatel961 3 месяца назад
I guess you forgot to put how to send the user_prompt Screen to email. if not is was there a point of user_prompt page
@MyDFIR
@MyDFIR 3 месяца назад
Nope, truth be told, I couldn't find the option to send that as an email. If you find out how, let me know! The user prompt page is there to have the user select if they want to isolate or not as most of the time we never want to isolate automatically. You could probably change this to be sent to slack/email with a yes or no option as well but I'll leave that you/other curious individuals who want to learn more!
@evanj51
@evanj51 2 месяца назад
BTW, idk if you know but a channel called Cynik post a video pretty much copying this with no credit to you! Idk how this works as far as stealing content, but he made his own video doing everything you did but calling it his own. I didn't see credit to you anywhere.
@MyDFIR
@MyDFIR 2 месяца назад
Haha wow thanks for letting me know! It is pretty much one for one, even my diagram.
@evanj51
@evanj51 2 месяца назад
@@MyDFIR exactly.
@ItsCynik
@ItsCynik 3 месяца назад
Sigma MyDFIR
Далее