• ATTENDEE
    • Registration
    • Safety
    • Code of Conduct
  • IN-PERSON
    • Keynotes
    • Briefings
    • Workshops
    • Speakers
    • Sponsors
  • VILLAGES
    • Villages
    • Contests
    • Austin
    • Code of Conduct
  • SPONSORS
    • Our Sponsors
    • Business Hall
    • Become a Sponsor
    • Our Mission
  • ABOUT
    • Call For Everything
    • Discord
    • CPE Credit
    • Privacy Policy
  • Code of Conduct
Log In
All Sessions
Speakers

Liunx Threat Detection

  • Workshop Starts: Friday, September 23, 2022 2:00 pm
  • Workshop End: Friday, September 23, 2022 4:00 pm
  • Workshop: Liunx Threat Detection with an Attack Range
  • Technology: Attack Range
  • Company: Splunk
  • Seats: 50
  • Audience: Beginner to Intermediate
  • Floor: Floor 1 - Room 2
  • Room: 2
  • Location: Floor 1 - Room 2
  • Briefing Type: 2hr Hands-On Workshop

Tech: 

  • Network Security |
  • Containers |
  • Defense |
  • Application Security |
  • Applied Security |
  • Cloud Security |
  • Offense |
  • DevSecOps |
  • Malware

The release of Microsoft Sysmon for Linux gives defenders new opportunities for monitoring, management, and detection development focusing on Linux operating systems.  The Splunk Threat Research Team has developed several analytic stories addressing Linux threat detection. In this presentation, presenters showcase how to use the latest Splunk Attack Range in order to replicate, record, analyze and develop detections based on Linux Sysmon data. We will also cover the importance of monitoring and hardening Linux systems, as well as available Splunk SOAR tools in order to automate investigation and response.

  • $whoami
  • Why Linux
  • Linux Sysmon TA
  • Splunk Attack Range Intro
  • Splunk Attack Range – building a Linux environment for threat replications, simulation and research
  • Detecting Linux Exploitation
  • Detecting Linux Post-Exploitation
  • Splunk SOAR playbooks for investigating and automating defense
  • Q&A

Speaker:

Rod Soto

Privacy  |  Disclaimer

© 2021 TexasCyber, All Rights Reserved.

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.