OSSEC Email Alert Suggestions

24 views
Skip to first unread message

Buddha Man

unread,
Jun 13, 2019, 12:19:52 PM6/13/19
to ossec-list
If you were going to create a top ten alerts email from OSSEC logs, I just wondering what folks would alert on?

What's the best way to detect fraudulent privileged account usage? I find it very challenging  to pick it out from legit activity. Maybe authentication without a password to detect hash usage / mimikatz?

What are some of the other queries folks try to pick out evil from all the noise?
Reply all
Reply to author
Forward
0 new messages