Webcast: Let’s Talk About ELK Baby, Let’s Talk About You and AD
ID: 260e8501-9057-5c02-af88-7d589d07d854
STIX ID: report--260e8501-9057-5c02-af88-7d589d07d854
Feed Name: Black Hills Infosec Blog
This webcast summary from Black Hills Information Security outlines guidance for improving detection and logging on Windows environments, demonstrating Sysmon, ELK (with ElastAlert), Windows Event Forwarding/Winlogbeat, and the Atomic Red Team framework. It provides timestamps and links to slides for a demo-driven presentation that emphasizes AD best practices, endpoint optics, and using open-source tools to reduce time-to-detection and refine alerting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
