RTHVM Save

Resolvn Threat Hunting Virtual Machine

Project README

RTHVM

The Resolvn Threat Hunting Virtual Machine (RTHVM) is a training resource used during a 2019 Packet Hacking Village workshop titled Intel-driven Hunts for Nation-state Activity Using Elastic SIEM.

In this workshop, participants analyzed Windows event logs of known malicious activity from various stages of the attack lifecycle. With key indicators identified, participants built Elastic SIEM Timelines for repeatable detection of MITRE ATT&CK techniques.

Workshop Slides
Virtual Machine

Open Source Agenda is not affiliated with "RTHVM" Project. README Source: RESOLVN/RTHVM
Stars
127
Open Issues
0
Last Commit
3 years ago
Repository

Open Source Agenda Badge

Open Source Agenda Rating