Splunk [Enterprise Security] 2019 .conf Videos w/ Slides

Post-Pwn3D: Using Splunk Enterprise and Splunk Enterprise Security for Incident Response and Forensic Analysis [Splunk Enterprise, Splunk Enterprise Security]


Listen Later

After breaches, incident response teams often end up with an overwhelming amount of forensic evidence data, including disk images, memory captures, PCAP, and more. We'll show you how one of our IR/forensics teams is ingesting this data into Splunk to answer the who, what, where, when and why of breaches. Our presentation will show you how to use Splunk Enterprise and Splunk Enterprise Security for Incident Response (IR) workflow tracking and reporting on multi-source forensic data captures.

Speaker(s)
Josh Wilson, Consulting Engineer, August Schell
Dave Martin, Supervisory Special Agent, Federal Bureau of Investigation

Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1796.pdf?podcast=1577146234

...more
View all episodesView all episodes
Download on the App Store

Splunk [Enterprise Security] 2019 .conf Videos w/ SlidesBy Splunk