RedGalahad 

22 Followers
53 Following
71 Posts

Security Engineer making his way through the world.

Learning and working.

@Ciro_Villa What an awesome picture, Crazy to think how massive some of those craters are
Anyone Remember SSHD Drives? did anyone actually use them?
@natesubra Interesting to know, but jesus thats creepy
@Sysengineer you can? You can mute whole communities or individual channels.
@synackbar that's basically what I need to do, there's no pre built FileBeat pipeline, so I need to make one, but I don't know how. I'm in over my head, but it's how I learn 😂
@synackbar I'm wanting to add in all the logs and alerts from other platforms like ESET, so I can see all of them in the same place basically. i will add in the windows logs too at some point

So I've had a poke around Security onion, and obviously, I'm setting this all up from scratch with ZERO existing knowledge of how to do any of this.

I'm a little lost if I'm honest, I know I can ingest device alerts through the Wazuh Agent. but I want to ingest data from existing services.. ESET for a start.
I think i can do this through SYSLOG but that requires knowledge of ElasticSearch it seems, is anyone any good with ElasticSearch and can give me a rundown?

#infosec #securityonion #SoC #threathunting

Took me two hours to work out why it wouldn't lold the WebUI. But finally..

I'm In.

@marylizcuba I suppose like asking the post office to tell you what your address is, so that you can receive mail

Also, I've set up a monthly subscription to donate to @jerry to support the infosec instance.

I'm a strong believer in "Pay for the product, don't be the product".
Lets keeps this train going :)

https://liberapay.com/Infosec.exchange/

Infosec.exchange's profile - Liberapay

This will fund operations and hosting costs for the infosec.exchange Mastodon instance. I greatly appreciate any and all donations.

Liberapay