SIEM, EDR, XDR, MDR & SOAR | Cybersecurity Tools and Services | Threat Monitoring

  Рет қаралды 72,899

Cyber Gray Matter

Cyber Gray Matter

2 жыл бұрын

Hey everyone! Today's video is going to be on various cybersecurity tools, including SIEM, EDR (endpoint detection and response), XDR (extended detection and response), MDR (managed detectionand response), and SOAR (security orchestration, automation, and response). These are tools that an organization may choose to use to defend their network. As a SOC analyst, your job may be to monitor the SIEM and respond to alerts coming from your EDR solution. You might also use a SOAR solution where you create workflows and specialize in the automation side of cybersecurity. Having a fundamental understanding of these five tools will help you be prepared not only for the Security+ but also prospective interviews. As always, thank you so much for watching, and I hope you find this video beneficial!
cybergraymattir?t...
Links: www.crowdstrike.com/cybersecu...
www.crowdstrike.com/cybersecu...
www.sentinelone.com/blog/unde...
First track: Over The Ocean by | e s c p | escp-music.bandcamp.com
Music promoted by www.free-stock-music.com
Attribution 4.0 International (CC BY 4.0)
creativecommons.org/licenses/...
Second track: Lazy Aftermoon by | e s c p | escp-music.bandcamp.com
Music promoted by www.free-stock-music.com
Attribution 4.0 International (CC BY 4.0)
creativecommons.org/licenses/...

Пікірлер: 53
@NK-iw6rq
@NK-iw6rq 11 ай бұрын
One of the best videos i've seen explaining all of this !
@bluejay8972
@bluejay8972 Жыл бұрын
This is well-explained and adheres to industry standard. Great job.
@cybergraymatter
@cybergraymatter Жыл бұрын
Thank you so much! I hope you stick around and check out my upcoming videos :)
@manojmahajan30
@manojmahajan30 7 ай бұрын
Clear and crisp information, I was looking for something like this for a long time, thank you so much for sharing.. Already subscribed to your content.. 🙂
@sunderdase3511
@sunderdase3511 Жыл бұрын
Nicely explained, thank you!
@rv1915
@rv1915 Жыл бұрын
Great video for eager learners
@Seansaighdeoir
@Seansaighdeoir Күн бұрын
Very interesting and informative, thanks for sharing. Found the music somewhat distracting - good info doesn't need accompaniment.
@garrisonsimon
@garrisonsimon Жыл бұрын
Thanks for this great video! I learned a lot!
@DunOpondo
@DunOpondo Жыл бұрын
Awesome video. 👍🏿
@brooklynzoo81
@brooklynzoo81 2 жыл бұрын
Great content, Thanks! Subscribed.
@cybergraymatter
@cybergraymatter 2 жыл бұрын
Wow, thank you! :)
@gkcamden9050
@gkcamden9050 Жыл бұрын
Nice overview of these tools. Concise and too the point! Thank you. Subscribed with the bell turned on!
@cybergraymatter
@cybergraymatter Жыл бұрын
Thank you so much! It really means a lot! :)
@sametsahin-eh3qj
@sametsahin-eh3qj 20 күн бұрын
cool video, next time you should put out the music
@syh7522
@syh7522 2 жыл бұрын
great content.. perfect job 👍👍
@cybergraymatter
@cybergraymatter 2 жыл бұрын
Thank you so much for watching and leaving a comment!
@AboodSpiN
@AboodSpiN 6 ай бұрын
Amazing video thank you so much!
@cybergraymatter
@cybergraymatter 6 ай бұрын
You're so welcome!
@paragbarot2638
@paragbarot2638 2 ай бұрын
I hope in next videos you will lower the background music. By the way this video is very informative.
@NostalgistGuy
@NostalgistGuy 8 ай бұрын
Thank you.
@951niels
@951niels Жыл бұрын
great vid
@kareemelfetiany2042
@kareemelfetiany2042 Жыл бұрын
Thanks a lot.
@KeithChungMusic
@KeithChungMusic 11 ай бұрын
well explained
@arsalananwar3397
@arsalananwar3397 Жыл бұрын
nice info
@yuvrajsingh-un7xo
@yuvrajsingh-un7xo 9 ай бұрын
Awesome explanation Mam Have you any idea of next-gen firewall
@alexanderyelich817
@alexanderyelich817 Жыл бұрын
Thanks!
@cybergraymatter
@cybergraymatter Жыл бұрын
I appreciate it!
@DavidCorlette
@DavidCorlette 2 ай бұрын
This video is good, but next-gen AV has leveraged behavioral detection for zero-days for a long time - well before EDRs came on the scene. The real distinction between an NGAV and an EDR is that NGAV tries to take a black-and-white approach - it is or is not malicious. If a threat is classified as malicious (by actual signature-type detection or by hitting some statistical threshold in behavioral detection) the threat will be blocked and quarantined. The difference with EDR is in the name - EDR will also notify (Detect) about "grey area" potential threats that can't be confidently classified as malicious, and provide the telemetry (events) needed so that a human can investigate and make a decision. EDRs also provide post-attack remediation (Response) tools such as device isolation, remote shells, etc. Good EDR solutions include comprehensive NGAV so that you don't waste a lot of time chasing potential threats that could easily have been blocked by an NGAV.
@shia4363
@shia4363 Жыл бұрын
Great video! Can you suggest EDR and XDR solutions?
@swathiguru
@swathiguru 11 ай бұрын
Kudelski Security
@peteallennh
@peteallennh Жыл бұрын
Great content! Lose the muzak 🙂
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for the comment! I am getting 50/50 on the music and have lowered it for more recent videos. It really helps with any background blips to have at least something.
@CrazyFanaticMan
@CrazyFanaticMan 2 жыл бұрын
How would I classify a MITRE ATT&CK attack as XDR, MDR or EDR?
@cybergraymatter
@cybergraymatter 2 жыл бұрын
Thanks for your comment! I wouldn't classify an attack by the way it was detected. I hope this makes sense.
@ahmedyousufibrahim980
@ahmedyousufibrahim980 Жыл бұрын
Greate I give you subscribe ❤
@rdstill
@rdstill Жыл бұрын
The background music was really distracting
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for your reply! The levels were still a work in progress and vary depending on what device one is listening on. I have toned it down on newer videos.
@smileybuddy_
@smileybuddy_ Жыл бұрын
Where u from? Country
@cybergraymatter
@cybergraymatter Жыл бұрын
USA
@19ceda92
@19ceda92 Жыл бұрын
would be a great video without that load music in the background..
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for leaving a comment! I have been working on an acceptable level for music. It's been a work in progress.
@AE-nt3jj
@AE-nt3jj Жыл бұрын
You also sound impatient with such speed of speech
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for your input! I'm a naturally fast speaker and try and slow things as it is. You're welcome to use the speed adjustment if you're having difficulty understanding.
@indosyncrasies
@indosyncrasies 10 ай бұрын
why the music???? It just takes away from the otherwise good content you have created.
@cybergraymatter
@cybergraymatter 9 ай бұрын
I thought it would add some excitement. I am considering reuploading without the music.
@GrowthMindset9
@GrowthMindset9 Жыл бұрын
Remove the background music, the content is good.
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for the comment! I have it to help with audio blips but have turned it down in more recent videos
@ctjmaughs
@ctjmaughs Жыл бұрын
Amazed how wrong this video is. Alerts
@cybergraymatter
@cybergraymatter Жыл бұрын
Thanks for your comment! I am happy to make any notations in the video if you've spotted an error. For the mention of alerts, events and incidents: Security events are continuously happening, as any changes could be a regular, everyday occurrence within the network. This means they aren't necessarily malicious. Alerts are still events, but they indicate a change or that warrants investigating. Finally, incidents can still be a singular event or alert, or a series of those. They may require a lengthy investigation with a report and can even be a breach at higher levels.
@ctjmaughs
@ctjmaughs Жыл бұрын
@@cybergraymatter It seems your are going with the Mandiant Methodology of alerts, events and incidents. I definitely don't agree with it but I do understand. I go with the alerts are more like logs and multiple alerts can be part of an event. Incidents can comprise of multiple events and tend be higher fidelity.
@cybergraymatter
@cybergraymatter Жыл бұрын
@ctjmaughs I've seen multiple ways things are classified within various organizations and industries for different reasons. Some places call an incident of any severity an incident, while others are called incident a or incident b, etc. I wouldn't say either is wrong but dependent upon the place; though, if it were me who was tasked with designing a program from the ground up, I would use the definitions shown in this video. In the link below, Daniel Miessler also mentions your variation of events and alerts and states that there are differences based on industry. danielmiessler.com/study/event-alert-incident/
@AE-nt3jj
@AE-nt3jj Жыл бұрын
You speak fast and sound like a robot. You did it on purpose
@ryanknight6360
@ryanknight6360 7 ай бұрын
What a weird response lol. Slow the speed of the video down if you’re slow
EDR vs. XDR: A Practical Guide to Next-Gen Cybersecurity
24:27
Prabh Nair
Рет қаралды 14 М.
1❤️#thankyou #shorts
00:21
あみか部
Рет қаралды 77 МЛН
Is it Cake or Fake ? 🍰
00:53
A4
Рет қаралды 17 МЛН
Sprinting with More and More Money
00:29
MrBeast
Рет қаралды 176 МЛН
EDR, MDR & XDR Explained
10:33
Pro Tech Show
Рет қаралды 27 М.
MITRE ATT&CK Framework for Beginners
7:53
Cyber Gray Matter
Рет қаралды 50 М.
What is XDR vs EDR vs MDR?  Breaking down Extended Detection and Response
8:54
The CISO Perspective
Рет қаралды 181 М.
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,2 МЛН
SOAR! What is it good for? Absolutely everything. (1138)
45:57
Palo Alto Networks Ignite
Рет қаралды 14 М.
Overview of SIEM : Most Pratical Appraoch
14:25
Prabh Nair
Рет қаралды 37 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
SOC Tools - SIEM EDR XDR MDR and SOAR Explained
9:45
InfoSec Guardians
Рет қаралды 1,5 М.
i love you subscriber ♥️ #iphone #iphonefold #shortvideo
0:14
Cadiz smart lock official account unlocks the aesthetics of returning home
0:30
Bluetooth Desert Eagle
0:27
ts blur
Рет қаралды 6 МЛН
Где раздвижные смартфоны ?
0:49
Не шарю!
Рет қаралды 913 М.