The long-awaited update to Sysmon is here!
Microsoft has recently released version 15. This updated version of the popular logging tool includes new features and provides responders insight into endpoint behavior.
In this Anti-Cast, Gerard Johansen, digital forensics practitioner and course author of Enterprise Forensics and Response will walk through how Sysmon can aid in incident investigations.
Gerard will provide an overview of Sysmon, including what data analysts can see, how to deploy and configure, and finally looking at how Sysmon can aid in incident investigations. He’ll walk you through how configurations can be tailored, local and remote acquisition of Sysmon log files, and finally how to analyze various Tactics and Techniques commonly seen in incident investigations.
Register for this July 19th Anti-Cast here.
Webcast starts at 12 p.m. EDT, be sure to tune in at 11:30 a.m. EDT for PreShow Banter™!
Chat with your fellow attendees in the Antisyphon Discord server here: https://discord.gg/antisyphon — in the #webcasts-livestreams channel
View the slides from this webcast below.