利用 Yamato Security OSS 工具和社区驱动的知识执行数字取证与事件响应 (DFIR) 和威胁狩猎.pdf

编号:981710 PDF 54页 4.70MB 下载积分:VIP专享
下载报告请您先登录!

利用 Yamato Security OSS 工具和社区驱动的知识执行数字取证与事件响应 (DFIR) 和威胁狩猎.pdf

1、#SECTORCA SecTorCAPerforming DFIR and Threat Hunting with Yamato Security OSS Tools and Community-Driven KnowledgeAkira Nishikawa and Fukusuke Takahashi#SECTORCA SecTorCAThank You for Your Understanding:Non-Native English Speakers#SECTORCA SecTorCAWe are going to try to make this a fun presentation

2、anyway!#SECTORCA SecTorCAAgenda Self-Introduction About Yamato Security and tools and resources Hayabusa Sigma Takajo Future Plans#SECTORCA SecTorCASelf-IntroductionAkiraNishikawaFukusukeTakahashi First core developer of Hayabusa 2007 Freelance engineer 2021 SaaS product security Now working at Kami

3、nashi AWS Community Builder Latest core developer of Hayabusa DFIR,OSINT,SOAR at NTT-DATA CERT I fix bugs in open-source projects and bug hunt for vulnerabilities in my free time#SECTORCA SecTorCAAbout Yamato Security“Yamato”(大和)=“Japan”First created by Zach Mathis in 2012 to create a security commu

4、nity in Western Japan.Free/low-cost high-quality security training around the country Now over 2000 registered members Developing various open-source DFIR tools and resources since 2020.#SECTORCA SecTorCAYamato Security tools and resources Hayabusa:DFIR timeline generator using native Sigma rules fo

5、r Windows event logs Takajo:Hayabusa results analyzer Yamato Securitys Windows Event Log Configuration Guide For DFIR And Threat Hunting Curation of Sigma Rules for Windows Event Logs Deprecated:WELA(Windows Event Log Analyzer)#SECTORCA SecTorCAHayabusa?Who here has used or knows about Hayabusa?#SEC

6、TORCA SecTorCAAbout Hayabusa https:/ Fast forensics and Threat Hunting CLI tool for Windows event logs Developed in Rust so it is very fast,cross-platform and safe from anti-forensics memory corruption exploits Many features:logon summaries,keyword searches,keyword extractions,sigma-based DFIR timel

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(利用 Yamato Security OSS 工具和社区驱动的知识执行数字取证与事件响应 (DFIR) 和威胁狩猎.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠