Personal
Risk-management
Certification
Infosec management
Strategy
Malware
Career
Defcon
Ru
Siem
- Monitoring local Windows users - Pt. 2 - Tracking deleted user accounts
- Monitoring local Windows users - Pt. 1 - Tracking new user accounts
- Catching successful RDP connections with ArcSight ESM
- Operational monitoring of WEF Log sources in ArcSight
- Installing Custom FlexConnector for the Exchange Admin Audit Logs
- Getting MS Exchange Admin Logs details with the custom PS script
- Developing custom ArcSight parser for the Sysmon logs
- ArcSight - Basic CheckPoint Rule Pack Pt.3
- ArcSight - Basic CheckPoint Rule Pack Pt.2
- ArcSight - Basic CheckPoint Rule Pack Pt.1
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt.3
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 2
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 1
- What to consider before buying SIEM
Vpn analytics
Arcsight esm
- Monitoring local Windows users - Pt. 2 - Tracking deleted user accounts
- Monitoring local Windows users - Pt. 1 - Tracking new user accounts
- Catching successful RDP connections with ArcSight ESM
- Operational monitoring of WEF Log sources in ArcSight
- Installing Custom FlexConnector for the Exchange Admin Audit Logs
- Getting MS Exchange Admin Logs details with the custom PS script
- Developing custom ArcSight parser for the Sysmon logs
- ArcSight - Basic CheckPoint Rule Pack Pt.3
- ArcSight - Basic CheckPoint Rule Pack Pt.2
- ArcSight - Basic CheckPoint Rule Pack Pt.1
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt.3
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 2
- ArcSight - AnyConnect VPN Correlation Rules Pack - Pt. 1
Vulnerability assessment
Firewall analytics
Endpoint analytics
Exchange
Flexconnector
Windows
Operations
Wef
Rdp
Local users
Outlook