Threat Hunting with ELK Workshop (InfoSecWorld 2017 and TBD)
- Contact us if you would like a copy.
- Contact us if you would like a copy. Alternatively, simply install the ELK stack in a Linux distro of your choice (bare metal or VM).
- https://technet.microsoft.com/en-us/sysinternals/sysmon
- https://www.rsaconference.com/events/us17/agenda/sessions/7516-How-to-Go-from-Responding-to-Hunting-with-Sysinternals-Sysmon
Sample data from: