Changing Network Detection
Using Bro and Distributed Computing Concepts Mike Reeves @TOoSmOotH
Changing Network Detection Using Bro and Distributed Computing - - PowerPoint PPT Presentation
Changing Network Detection Using Bro and Distributed Computing Concepts Mike Reeves @TOoSmOotH Who are you and why are you talking to me? 16 years in InfoSec, 19 years total IT Work at FireEye Huge Bro fan Lots of
Using Bro and Distributed Computing Concepts Mike Reeves @TOoSmOotH
deployments
etc
Interwebs
Outbound Access
VPN
Lateral Movement
3rd Party DMZ
network performance - just sucks for people trying to do detection
Site 1 Site 2 Site 3
backend
Master of Masters Minion Master Minion Master Minion Master Minion Minion Minion Minion Minion Minion Minion Minion Minion Github
Log Ingest Rabbit MQ Index Rules Archive
Database
logs,host logs
Enterprise Security Monitoring