Тёмный

How To Automate Cyber Threat Intel With Graylog and Greynoise. Auto Detect Malicious IPs! 

Taylor Walton
Подписаться 19 тыс.
Просмотров 8 тыс.
50% 1

Опубликовано:

 

2 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 18   
@Foxi352
@Foxi352 Год назад
This series is pure gold. Thank you very much for investing a lot of time making it ! 🍻
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Thanks for watching!
@Bobtb
@Bobtb 4 месяца назад
Apparently this is no longer functional using Community API keys. This is the message I get in Graylog version 6.0.0: "Cannot perform lookup without a GreyNoise Enterprise subscription. Check API key and restart Data Adapter."
@carlitoang9509
@carlitoang9509 3 месяца назад
can't use Greynoise free anymore :( Graylog asking for the subscription one
@kobramadani6588
@kobramadani6588 5 месяцев назад
Thank you
@luismontoya9925
@luismontoya9925 Год назад
It so awesome Taylor! The current community plan of Greylog just allow to do 50 IP lookup per week. I looked prices the basic plan costs $27,000 dlls/year , definitly I can't pay it, it's to much for me :C I hate to be poor lol
@gguestdub3518
@gguestdub3518 Год назад
hello my bro nice to meet u, i hope u are well , could you help me a create input office 365 audit logs on graylog please i have version 4.2
@miguelsaiz8151
@miguelsaiz8151 Год назад
Hi Taylor ! I would like to work for you in SOCFortress
@MsRope93
@MsRope93 Год назад
is it possible to the same with OpenSearch instead of Graylog?
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
If your logs are already stored within OpenSearch, you'd need to write a script that makes an API request to opensearch to collect the IPs, then loop through and submit the IPs to Greynoise and then make another API call to OpenSearch to PUT the new fields...much easier to do with Graylog :)
@eladdolev3507
@eladdolev3507 Год назад
@@taylorwalton_socfortress Interesting Point, is not also according to your SOC Series, the GrayLog is used for all normalisation and other functions, but then Graylog sends the Logs to Storage into the Wazuh Indexer ?
@eladdolev3507
@eladdolev3507 Год назад
Great Video and great Series Taylor! I wonder about the Intel Enrichment part. On your original Plan you used Misp & OpenCti, have u now changed both into Graynoise?
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Stay tuned :)
@quikmcw
@quikmcw Год назад
but you can do all of this from within Wazuh and it is rather easy. Then you don't need to spin up another server and another server.....etc.
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Hey Michael, you definitely could! I just think Graylog makes it much easier when it comes to ingesting various log sources outside of wazuh, log normalization, log routing, data caching and just gives us more freedom over our logs. Thanks for watching!
@mean7429
@mean7429 Год назад
Thank you
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Thanks for watching!
@townsotolo5528
@townsotolo5528 Год назад
So fun! Get to know the secret = Promo_SM!!
Далее
Standardize Your SIEM Logs Now!
12:22
Просмотров 5 тыс.
ХОККЕЙНАЯ КЛЮШКА ИЗ БУДУЩЕГО?
00:29
ВЫЗВАЛ ЗЛОГО СОНИКА #Shorts
00:38
Просмотров 58 тыс.
Quarantine Malware with Wazuh + YARA
25:41
Просмотров 10 тыс.
this Cybersecurity Platform is FREE
39:46
Просмотров 574 тыс.
Top 6 Most Popular API Architecture Styles
4:21
Просмотров 915 тыс.