Securing Windows End Points: Windows Logs, Sysmon and QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Securing Windows End Points: Windows Logs, Sysmon and QRadar

Agenda:

• Brief White Board Introduction
• Rules Capabilities in the Endpoint Content Extension
• Bringing standard Windows and Sysmon Logs to QRadar with Win Collect
• Customer Experiences
• Question and Answers from our Panelists

Register here

Summary

None would argue that Windows systems can use all the protection we can give them. Not only they are under constant attacks, but also new vulnerabilities are discovered much too frequently.

Standard Windows logs have become better and QRadar has free rules that can detect many attacks. If you enhance those Windows logs with the free Sysmon from Microsoft, QRadar can do real wonders detecting sophisticated and obfuscated attacks.

To prove this, I have pulled two of the developers of those rules (Gladys Koskas and Mo) who are going to show concrete examples of that detection. Also I have lined up Wincollect developer (Josh Ryan) who is going to show how easy it is to set Wincollect to send only significant Sysmon logs to QRadar with minimal EPS impact. After that, we will have two engineers (Kevin and Stephen) from one QRadar customer sharing how these technologies have enable them to uncover bad guys while trying.

We will close the session with 15 minutes for you to ask questions to these distinguished professionals.

Speakers

Jose Bravo
Security Architect, North America at IBM Security

Gladys Koskas
QRadar Content Development Lead at IBM Security

Mololuwa Josiah
Security Content Developer at IBM Security

Josh Ryan
Software Engineer at IBM Security

Kevin Wood
Director, CISO

Stephen Murphy
Associate Director, Cyber Security Operations

Register here



#QRadar
Event Image
When:  May 10, 2022 from 10:00 AM to 11:00 AM (ET)

Contact

Claudia Tate

claudia.tate@ibm.com