Host-Centric Log Sources: Log sources that capture events that occured within or related to the host., Windows Event Logs, Sysmon, Osquery., A user accessing a file., A user attempting to authenticate., A process Executing Activity., A process adding/editing/deleting a registry key or value., Powershell execution., Network-Centric Log Sources: Logs are generated when the hosts communicate with each other or access internet to visit a website., Some network-based protocols are SSH, VPN, HTTP/s, FTP., SSH connection., A file being accessed via FTP., Web traffic., A user accessing company's resources thorugh VPN., Network file sharing activity.,

Tabela rankingowa

Motyw

Opcje

Zmień szablon

Przywrócić automatycznie zapisane ćwiczenie: ?