Really fun costume theme on this week's #ThursdayDefensive!
Thanks again to @rj_chap for dropping awesome insights on latest ransomware trends and mitigations - watch out for those unauth RMM tools!
Join us next week to hear from defensive pro @therealwlambert!
Pssst, my Linux Forensics class is now four days long-- two days of new material, labs, and a capstone exercise! And, yes, the update is freely available https://t.co/ATEx5R6sjv
Want to leverage threat intel from @MISPProject , @alienvault OTX, @abuse_ch , MalwareBazaar and other platforms for enrichment with @securityonion? 🧅🛡️🔍
We can do this with the @elastic's (Filebeat) Threat Intel module and an enrich pipeline/policy👇:
https://t.co/vCVtloYFVv
With Cases, defenders can:
✅Track investigations, creating cases inside of SOC
✅Escalate events to a new or existing case
✅Add observables or attachments to a case
✅Hunt for IOCs straight from a case
In CASE you were wondering...yes, it's FREE! 🧅🛡️
Had a great time presenting at the @BlueTeamCon webinar tonight about cloud logging, monitoring, and #securityonion! Thanks to everyone that tuned in! I'll soon be sending out a few tweets about some of the items/tools we discussed. TTFN. #BlueTeam#NSM#DFIR#infosec