Personal
  
 
  Risk-management
  
 
  Certification
  
 
  Infosec management
  
 
  Strategy
  
 
  Malware
  
 
  Career
  
 
  Defcon
  
 
  Ru
  
 
  Siem
  
      
    
      
      
      - Monitoring local Windows users - Pt. 2 - Tracking deleted user accounts
- Monitoring local Windows users - Pt. 1 - Tracking new user accounts
- Catching successful RDP connections with ArcSight ESM
- Operational monitoring of WEF Log sources in ArcSight
- Installing Custom FlexConnector for the Exchange Admin Audit Logs
- Getting MS Exchange Admin Logs details with the custom PS script
- Developing custom ArcSight parser for the Sysmon logs
- ArcSight - Basic CheckPoint Rule Pack Pt.3
- ArcSight - Basic CheckPoint Rule Pack Pt.2
- ArcSight - Basic CheckPoint Rule Pack Pt.1
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt.3
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 2
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 1
- What to consider before buying SIEM
Vpn analytics
  
 
  Arcsight esm
  
      
    
      
      
      - Monitoring local Windows users - Pt. 2 - Tracking deleted user accounts
- Monitoring local Windows users - Pt. 1 - Tracking new user accounts
- Catching successful RDP connections with ArcSight ESM
- Operational monitoring of WEF Log sources in ArcSight
- Installing Custom FlexConnector for the Exchange Admin Audit Logs
- Getting MS Exchange Admin Logs details with the custom PS script
- Developing custom ArcSight parser for the Sysmon logs
- ArcSight - Basic CheckPoint Rule Pack Pt.3
- ArcSight - Basic CheckPoint Rule Pack Pt.2
- ArcSight - Basic CheckPoint Rule Pack Pt.1
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt.3
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 2
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 1
Vulnerability assessment
  
 
  Firewall analytics
  
 
  Endpoint analytics
  
 
  Exchange
  
 
  Flexconnector
  
 
  Windows
  
 
  Operations
  
 
  Wef
  
 
  Rdp
  
 
  Local users
  
 
  Outlook