Chapters
Intro
Intro
0:00
Intro
0:00
Microsoft Security
Microsoft Security
2:25
Microsoft Security
2:25
Consuming Indicators: Community
Consuming Indicators: Community
9:33
Threat Research Methodology
Threat Research Methodology
10:16
Behavior: Windows Security Events
Behavior: Windows Security Events
13:34
Let's Empower Others!
Let's Empower Others!
14:15
Let's Empower Others!
14:15
Mordor Project
Mordor Project
14:58
Mordor Project
14:58
Lateral Movement WMI Win32_Process Create
Lateral Movement WMI Win32_Process Create
17:34
Mordor Labs
Mordor Labs
21:27
Mordor Labs
21:27
Azure Resource Manager Service
Azure Resource Manager Service
21:42
Azure Resource Manager Templates
Azure Resource Manager Templates
21:59
The Shire (Windows)
The Shire (Windows)
22:15
The Shire (Windows)
22:15
Windows Event Collection
Windows Event Collection
22:49
Windows Event Collection
22:49
Kafkacat.conf: Azure Event Config
Kafkacat.conf: Azure Event Config
25:31
Kafkacat: Empire Lateral Movement via WMI
Kafkacat: Empire Lateral Movement via WMI
26:52
Azure Monitor HTTP Data Collector API
Azure Monitor HTTP Data Collector API
29:51
Python: HTTP Data Collector API
Python: HTTP Data Collector API
30:06
Plain Python: Proof of Concept Script
Plain Python: Proof of Concept Script
30:49
Azure Sentinel - Check Custom Logs
Azure Sentinel - Check Custom Logs
32:59
Azure Event Hub + Logstash + HTTP Data Collector API
Azure Event Hub + Logstash + HTTP Data Collector API
35:39
Azure Sentinel To-Go!: Custom Logs Pipe
Azure Sentinel To-Go!: Custom Logs Pipe
38:31
What's all this data?: ATT&CK Evals APT29
What's all this data?: ATT&CK Evals APT29
41:11
Lateral Movement: New Services Installed
Lateral Movement: New Services Installed
42:58
Roadmap
Roadmap
52:23
Roadmap
52:23
Q&A | Ask the speaker by submitting a question or upvote for questions
Q&A | Ask the speaker by submitting a question or upvote for questions
58:03
Sync to video time
Description
26Likes
1,363Views
2020Sep 14
Chapters
View all
View all
Transcript
Follow along using the transcript.
Show transcript
Microsoft Security Community
33.6K subscribers
Transcript
NaN / NaN
Show more