In this three-part Hands-on Hunting series Tanium veteran Paul Kelly walks you through how to detect, react, and recover from cyber incidents using Tanium Threat Response. Beginners to advanced will benefit from Paul's step-by-step tour through these features and recommended practices. Learn how to triage alert details, scope impact, investigate malicious endpoint activity, quarantine, remediate, and much more.
Tanium's Hands-on Hunting workshop builds on these concepts in a lab environment where you can learn these techniques at an even deeper level, guided by a seasoned trainer. Go to https://www.tanium.com/events/ to find an online or in-person event near you.
RESOURCES
Hands-on Hunting workshop - https://www.tanium.com/events/
Speak at Converge - https://converge.tanium.com - Austin, TX - November 14 -1 7, 2022
Threat Response Docs - https://docs.tanium.com/threat_response
Threat Response Community - https://community.tanium.com/s/threat...
What Is Threat Hunting and Why Does It Matter? https://endpoint.tanium.com/what-is-t...
CLARIFICATION
Multiple times Paul refers to Live Connection as "like console access". Note that Tanium does not provide direct remote console or shell access to endpoints. However, you do get access to live remote data like the file system browser and the live activity of process, file, registry, network, etc. In this respect it is "like" remote console access. See this docs page for more info: https://docs.tanium.com/threat_respon...
CHAPTERS
00:00 Intro
00:50 Announcements
01:58 Paul Kelly
02:20 Live Response
04:05 Snapshot, Saved Evidence, Live Response, Live Connection?
06:05 Saved Evidence
07:24 Process tree view
08:53 Saved Evidence
09:39 Enterprise question
10:55 Enterprise Hunting
12:58 Deploy Action
13:30 Enterprise Hunting
14:26 Resources
#InformationSecurity #CyberSecurity #ConvergedEndpointManagement #Windows #Linux #MacOS