March 4

Webinar Takeaway: Your Free and Open Source EDR Options!

0  comments

My key takeaways

  • carbon black was one of the first vendors as "black box flight recorder"
  • mitr uses cobalt strike and power... to simulate attacks
  • Good comparison: https://attackevals.mitre-engenuity.org/enterprise/evaluations.html?round=APT29
  • container security: Wazuh can inspect docker containers, carbon black was working with VMware, not docker or kubernetes
  • to start a hunt in velociraptor, hit the play button

Env

additional links


Tags

EDR


You may also like

What Fantasy Role-Playing Games Can Teach Us About Cybersecurity Roles

— And why your SOC might actually need a Bard 🐉⚔️ Cybersecurity teams are often compared to armies, fire brigades, or special forces. Personally? I think they’re much closer to a party of heroes in a classic fantasy role-playing game. No matter how many frameworks, SIEMs, or AI tools we summon, defending a digital kingdom

Read More

Lessons from Sun Tzu’s “The Art of War” in Cybersecurity: Timeless Wisdom or Outdated Tactics?

Introduction Sun Tzu’s "The Art of War" is a legendary strategic treatise written more than 2,500 years ago. Its enduring principles of warfare strategy have transcended military boundaries, influencing disciplines from business management to competitive sports. In today’s digital age, its relevance is increasingly apparent in the cybersecurity landscape, particularly for CISOs of medium-sized enterprises,

Read More