In this session we will discuss what are the different types of events we can pull from EDR backend to various SIEM solutions. We will mainly cover a step-by-step walkthrough of the “Activity Feed integration” with Trellix SIEM and how the same can be used for any other SIEM integration. During the session we will go through how to automate the activity feed using Docker and how to understand output.
Trellix is a global company redefining the future of cybersecurity. Our open and native extended detection and response (XDR) platform helps organizations confronted by today’s most advanced threats gain confidence in the protection and resilience of their operations. Trellix security experts, along with an extensive partner ecosystem, accelerate technology innovation through machine learning and automation to empower over 40,000 business and government customers.
🌐 | Visit Our Website
➡ https://trellix.com
📲 | Follow us on Social
➡ / trellix
➡ / trellixsecurity
#Trellix #Cybersecurity #LivingSecurity #XDR #EDR