Superior Threat Hunting by using Symantec Endpoint Security Complete.

Опубликовано: 30 Март 2026
на канале: Symantec
1,390
13

This video will show you how to make Symantec Endpoint Security Complete a vital part of your Threat Hunting strategy.

We'll start by showing you all aspects of analyzing Events including the different methods to query events, filter noisy events and what are the most meaningful fields to review within an event's details.

This video also shows you how to use Incidents (generated when an Incident rule condition is met) as a powerful tool to identify bad actors, attempts at privilege escalation and much more.


00:00 Introduction
00:40 Four effective methods to query for Events.
03:56 How to filter noisy or redundant event from your event queries.
05:32 What are the most meaningful fields in an event to include in my analysis?
08:04 How to use Incidents as a powerful tool in my Threat Hunting strategy.
13:07 Find out all activities of a suspicious process by expanding its process tree.
17:26 Identifying signs of a bad actor attempting to elevate their privileges to attack the system level