Episode Details
Back to Episodes7MS #495: Desperately Seeking a Super SIEM for SMBs - Part 5
Published 4 years, 4 months ago
Description
Today we continue our SIEM/SOC evaluation series with a closer look at one particular managed solution and how it fared (very well) against a very hostile environment: the Light Pentest LITE pentesting course! Spoiler alert: this solution was able to detect:
- RDP from public IPs
- Password spraying
- Kerberoasting
- Mimikatz
- Recon
netcommands - Hash dumping
- Hits on a "honey domain admin" account
- Users with non-expiring passwords
- Hits on the SSH/FTP/HTTP honeypot