Sysmon for Linux: Elevate Your Threat Hunting with Sysmon and Gravwell

Logo
Presented by

Corey Thuen, CEO, Gravwell

About this talk

Despite being initially released in 2021, many aren't aware of Sysmon's Linux capabilities. In this session, we’ll start with the basics of Sysmon on Linux, then quickly dive into expert-level strategies for threat detection and hunting using the Gravwell log aggregation platform. Learn how to streamline your workflow, detect anomalies, and protect your systems with real world techniques. What You'll Learn: - Key features of Sysmon for Linux and how to set it up. - Advanced threat hunting and detection techniques. - How to leverage Gravwell for threat analytics and event correlation. - Practical examples and live demonstrations.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (8)
Subscribers (1709)
Gravwell is a data platform with security lake features that enables teams to investigate, collaborate, and analyze data on-demand, from any source — all with unlimited data collection and retention.