Cybersecurity: SOC Analyst Mini-Course (Training)

Sdílet
Vložit
  • čas přidán 28. 06. 2024
  • With our SOC Analyst Mini-Course, students will obtain a better understanding of what a security operation centre is. From understanding the SOC Analyst workflow to frameworks & tools used, this is tailored for beginners and professionals who are looking to transition into cybersecurity specifically in the Security Operations domain.
    We end off with a practical hands-on lab to setup SecurityOnion and walkthrough a malicious PCAP together.
    Links
    SecurityOnion: github.com/Security-Onion-Sol...
    VirtualBox: www.virtualbox.org/wiki/Downl...
    SecurityOnion How To PCAP: docs.securityonion.net/en/lat...
    PCAP Used in Lab: www.malware-traffic-analysis....
    If you want to become a SOC Analyst grab the no BS SOC roadmap here
    mydfir.gumroad.com/l/SOC-Anal...
    _________________________________
    THE MYDFIR SOC ANALYST COURSE:
    With 8 chapters and 30+ hands-on labs tailored to security operations, I am focused on transforming you into a standout SOC analyst. Beyond tools, you'll master the investigation process and uncover hidden details. Let's make a real difference together.
    ▸Enroll here: academy.mydfir.com/p/soc
    _________________________________
    SIGN UP FOR FREE MENTORSHIP
    Getting started in Cybersecurity is difficult and you don't have to do it alone.
    Let me help you on your journey.
    ▸Sign up for FREE here: www.mydfir.com/mentorship
    _________________________________
    RECOMMEND COURSES FOR BEGINNERS:
    Coursera Google Cybersecurity Program
    Affiliate Link - imp.i384100.net/mydfir
    Microsoft Cybersecurity Analyst Professional Certificate
    Affiliate Link - imp.i384100.net/mydfir-MS
    Coursera Google IT Support Professional Certificate
    Affiliate Link - imp.i384100.net/mydfir-IT
    _________________________________
    PRODUCTS TO HELP YOU GET STARTED
    🗺️ 1-Year Cybersecurity Roadmap: mydfir.gumroad.com/l/roadmap
    📄 Resume Template: mydfir.gumroad.com/l/Resume-T...
    📑 Cover Letter Template: mydfir.gumroad.com/l/Cover-Le...
    🎙️ Interview Questions: www.mydfir.com/interview
    📚 Cybersecurity bookmarks: mydfir.gumroad.com/l/bookmarks
    _________________________________
    EARLY ACCESS & EXCLUSIVE VIDEOS
    Patreon: / mydfir
    _________________________________
    🕒 TIMELINE
    00:00 - Intro
    02:16 - What is a SOC
    09:38 - Common Threats
    11:57 - Frameworks & OSINT Tools
    19:39 - What is a SIEM
    21:27 - Hands On Lab
    _________________________________
    FOLLOW ME ON SOCIAL MEDIA:
    ▸Instagram: / mydfir
    ▸X: x.com/@MyDFIR
    Disclaimer: All opinions in my videos are solely my own. Some links provided are affiliate links!
    #cybersecurity #cybersecuritytrainingforbeginners #cybersecurityforbeginners #socanalyst #soc

Komentáře • 199

  • @kid809
    @kid809 Před 7 měsíci +47

    Awesome work! For once a detail video implementing the work flow of a SOC analyst.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +1

      Thank you very much!

  • @diegomed3364
    @diegomed3364 Před 6 měsíci +28

    Damn!! This is a min of $2500 Soc course and 4 days in less than 1h video ❤❤

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +5

      Haha thanks for watching! Hopefully you've learned something new 😀

  • @nathpatrick1104
    @nathpatrick1104 Před 4 měsíci +12

    This is undoubtedly the best teaching video on SOC/Cyber Security analyst. It was well detailed and so practical that beginners could understand the scope and the workings of a SOC analyst. Well done 👍.

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Thank you!! I appreciate that ❤️

  • @MrByonghacho
    @MrByonghacho Před 7 měsíci +2

    Course sounds like it'll be great. Can't wait!

  • @JoshAnthonyMcDowell
    @JoshAnthonyMcDowell Před 5 měsíci +5

    Best video on cyber security I’ve seen so far, thank you!!

    • @MyDFIR
      @MyDFIR  Před 5 měsíci +2

      Wow, thank you!

  • @pardonmagaba3643
    @pardonmagaba3643 Před měsícem

    This is by far the best channel that I have come across. Thank you Sir, what an amazing channel. You are destined for greatness.

    • @MyDFIR
      @MyDFIR  Před měsícem

      Wow, thank you!

  • @mutungidenissharp7783
    @mutungidenissharp7783 Před 2 měsíci +1

    The content here is top notch, grateful for this knowledge transfer. The course can't come soon enough-I'm eager to get started!

    • @MyDFIR
      @MyDFIR  Před 2 měsíci

      Great to hear! Thanks for watching ❤️

  • @sleepfighter3438
    @sleepfighter3438 Před 4 měsíci

    Wow! Thanks for the quality content. You are straight up legit!

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Thank you! Much appreciated

  • @MB-hz7wm
    @MB-hz7wm Před 4 měsíci +4

    After a year of traversing between instructors and courses, this is hands-down, the most streamlined, easy to understand instruction I've found.
    No distracting music, simple slides...
    Well done ~ thanks so much for giving back to the community in this way.

    • @MyDFIR
      @MyDFIR  Před 4 měsíci +1

      Thank you! That means a lot ❤️

  • @bebryan1201
    @bebryan1201 Před 6 měsíci +1

    This is absolutely fantastic. Thank you

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +2

      You're very welcome!

  • @stanleyzogli5695
    @stanleyzogli5695 Před 6 měsíci +2

    Great video with remarkable explanations.

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Many thanks! This was my first time doing something like this so I am happy it all worked out haha

  • @Cyber.Panda.
    @Cyber.Panda. Před 7 měsíci +3

    Awesome video!! Thanks for the lab 👏🏻👏🏻👏🏻🔥🔥

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +1

      Any time! Hopefully you learned something new!

  • @ShaySoFresh777
    @ShaySoFresh777 Před 5 měsíci +7

    Totally underrated channel!! How do you not have 1M subscribers??? I hope you blow up this year! This channel is so on point. No fluff, no bs - just straight knowledge and industry relevant content.

    • @MyDFIR
      @MyDFIR  Před 5 měsíci

      Thank you! ❤️ 1M would be crazy haha

  • @TheSilentLearner786
    @TheSilentLearner786 Před 7 měsíci +5

    You are great sir , super motive for every cyber enthusiastic love you

  • @eke313
    @eke313 Před 6 měsíci +3

    This guy is GOATED 💯

    • @MyDFIR
      @MyDFIR  Před 5 měsíci

      Haha thanks ❤️

  • @jasonlayton8760
    @jasonlayton8760 Před 7 měsíci

    Dude. You are awesome. I hope you win it all in life.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Thank you ❤️

  • @johnrodrigoasiado517
    @johnrodrigoasiado517 Před 4 měsíci +1

    This is awesome bro! the best i've seen so far and it will help us "aspiring to work in cybersecurity"❤

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Happy to hear that!

  • @Sp512
    @Sp512 Před 3 měsíci +2

    I am in the field for more than two years, randomly landed on your profile loved it!!!! So much good stuff still trying to figure out why this channel is so underrated. Hope you get more publicity in upcoming days!!! Keep up the good work! Looking forward to new learning video.

    • @MyDFIR
      @MyDFIR  Před 3 měsíci +1

      Awesome! Thank you!! ❤️

  • @irocz5150
    @irocz5150 Před 7 měsíci +1

    Amazing Work!!!!! Keep the good work

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Thank you! ❤️

  • @VerSatileMusliMah
    @VerSatileMusliMah Před 6 měsíci

    Great video! Eagerly waiting for full course 👍

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Thanks! ❤️

  • @iamrestnpieces
    @iamrestnpieces Před 7 měsíci +6

    Great job bro! The course was very detailed and beginner friendly. I am studying Cybersecurity and Information Assurance at WGU and your course content is pretty much the same as what we are being taught in college.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +2

      Oh wow, I am happy to hear that 😁 thank you for watching! I am here if you ever have any questions.

    • @iamrestnpieces
      @iamrestnpieces Před 7 měsíci

      Thanks!@@MyDFIR

  • @prashantmishra5691
    @prashantmishra5691 Před 4 dny

    Thanks for this amazing course.

    • @MyDFIR
      @MyDFIR  Před 4 dny

      You're very welcome! Hope you learned a lot ❤️

  • @oziegbeaaron5809
    @oziegbeaaron5809 Před 5 měsíci

    i am learning a lot from you
    keep up the good work

    • @MyDFIR
      @MyDFIR  Před 5 měsíci

      Glad to hear that! Thank you ❤️

  • @ishwaryanarayan1010
    @ishwaryanarayan1010 Před 4 měsíci

    Great video. Thank you 🙏

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Glad it was helpful!

  • @khalivalabi2089
    @khalivalabi2089 Před měsícem

    This is just great. thanks Steven

    • @MyDFIR
      @MyDFIR  Před měsícem

      Thanks for watching ❤️

  • @hobgoblin4614
    @hobgoblin4614 Před 6 měsíci +3

    Bro - This video was awesome/amazing. A+. Am going through some interviews now and this definitely helps. Looking forward to your labs, etc. will add myself to wait list!

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      Glad it was helpful! The full course will be 10x better than this 😃

    • @hobgoblin4614
      @hobgoblin4614 Před 6 měsíci

      @@MyDFIR can't wait. Do you have a timeline on when it will be released?

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +2

      @@hobgoblin4614 My goal is before May. I really want this to be something special

  • @ram_bam
    @ram_bam Před 7 měsíci +7

    I’m excited to watch this tomorrow. How do you manage two jobs at once?
    - edit - This was incredibly well done! You have a knack for teaching in a practical way.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +6

      Great question, not going to lie its not easy. Thankfully my 2nd job is not THAT bad so the workload is manageable but it sucks when I have an active incident on going.

  • @bulba888
    @bulba888 Před 7 měsíci

    Thats what doctor ordered, thx a lot

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Haha thanks for watching!

  • @cybersecdefender290
    @cybersecdefender290 Před 7 měsíci +1

    Keep up the good work!

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +1

      Thanks, will do!

  • @zeeshanansari-kl4tk
    @zeeshanansari-kl4tk Před 2 měsíci

    your all videos are very helpful , its have very informative things in it , as i am a Linux system admin and i also learn and study about cyber security from the different platform , the way you explain is very simple and good manner

    • @MyDFIR
      @MyDFIR  Před měsícem

      You are most welcome! Thanks for watching ❤️

  • @alanjaf9879
    @alanjaf9879 Před 4 měsíci

    Thank you ,very usefull chanel you operate on this platform. Best of luck, you will grow big soon here😀

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Thanks a lot 😊

  • @mohh4252
    @mohh4252 Před měsícem

    I like to see more videos. Very clear demonstration thank u

  • @Nate_Vee
    @Nate_Vee Před 4 měsíci

    Thanks for sharing this vital information

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Glad it was helpful!

  • @myNameIsEmanon
    @myNameIsEmanon Před 6 měsíci +1

    This is GREAT!

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      Thanks for watching! ❤️

    • @myNameIsEmanon
      @myNameIsEmanon Před 6 měsíci

      @@MyDFIR Thanks for posting. This is the exact content Ive been looking for. Im an embedded sys security researcher and know NOTHING about enterprise security. Your videos have been awesome.

  • @genjimccorkle5518
    @genjimccorkle5518 Před 2 měsíci +1

    Trying to make a jump right now from MSP to Network Technician to SOC. Hopefully your courses can help.

    • @MyDFIR
      @MyDFIR  Před 2 měsíci +1

      I hope so too! Let me know if you have questions 👍

    • @genjimccorkle5518
      @genjimccorkle5518 Před 2 měsíci

      @@MyDFIR No questions. Appreciate you reaching out. I am on the waitlist fyi.

  • @deanhaycox
    @deanhaycox Před 5 měsíci +1

    Loved this video, cant wait for the new SOC course. when is it out please :)? oh, and fantastic channel.
    Its nice to see someone talk about SOC training, skills and the job from somebody who as actually done it

    • @MyDFIR
      @MyDFIR  Před 5 měsíci +1

      Working hard on it, expect to release it by May at the latest. Could be earlier!

  • @RozzClips
    @RozzClips Před 7 měsíci

    Thank you so much, it helps alot.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Glad to hear that! Thank you ❤️

  • @getrobbed7818
    @getrobbed7818 Před 7 měsíci

    Thank you this is very informative.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +1

      You are very welcome. Thanks for watching ❤️

  • @jayantakumarbose4264
    @jayantakumarbose4264 Před měsícem

    Very good presentation and love from India ❤

    • @MyDFIR
      @MyDFIR  Před měsícem

      Thank you ❤️

  • @Eudawg101
    @Eudawg101 Před 3 měsíci

    Really great work.

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      Thanks a lot!

  • @godsblessings1924
    @godsblessings1924 Před 7 měsíci +1

    🔥🔥🔥

  • @Streetrack
    @Streetrack Před 7 měsíci +2

    This is pure gold!!!! I just passed my Cysa+ exam today and this walkthrough is much needed to gain some hands on experience. Question, Let's Defend or Cyber Defenders?

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Thanks and congratulations!!! Regarding LetsDefend vs CyberDefenders, I personally like CyberDefenders more but it all boils down to what you can afford. (Assuming you are talking about the paid courses) - Both will offer you with a lot of hands on skills.
      Hope that helps!

    • @Streetrack
      @Streetrack Před 7 měsíci

      @@MyDFIR Thanks Steven! Your content is amazing. Keep blessing us with your knowledge! 🫡

  • @brycesipes
    @brycesipes Před 7 měsíci +1

    Great content

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Thanks for watching ❤️

  • @GlobalEdukasiInfotamaSolusi
    @GlobalEdukasiInfotamaSolusi Před 4 měsíci

    This is awesome work...

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Thanks a lot 😊

  • @digitalapriko
    @digitalapriko Před 7 měsíci +1

    Great video

  • @melaronvalkorith1301
    @melaronvalkorith1301 Před 7 měsíci +1

    Looking forward to digging into this. Keep up the great work man!

    • @MyDFIR
      @MyDFIR  Před 7 měsíci +1

      Hope you enjoy it!

    • @melaronvalkorith1301
      @melaronvalkorith1301 Před 6 měsíci

      I am! You take the fundamentals and most important subjects and make them simple. You are clearly putting a lot of time, effort, and love into making MyDFIR a success. Keep up the great work, us newbies are lucky to have someone like you 🤟

  • @renewmediainc7663
    @renewmediainc7663 Před 6 měsíci

    everyday fire you are on fire very great video

  • @Nuhuh130
    @Nuhuh130 Před 4 měsíci

    I am to cybersecurity and I am seeking a job as a SOC analyst, this video is a big help! Thanks

    • @MyDFIR
      @MyDFIR  Před 4 měsíci +1

      Glad it was helpful!

    • @Nuhuh130
      @Nuhuh130 Před 4 měsíci

      @@MyDFIR any tips on how to land my 1st job

  • @Jesse_Johnson
    @Jesse_Johnson Před 6 měsíci

    Just found you!! This is phenomenal content. Refreshing. Need to collaborate with Dr. Gerry Auger. Cheers 🍻

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      Awesome! Thank you! Gerry is awesome, I’ve recommended folks over to his channel for GRC advice since that is not really my specialty 😅

  • @user-mr1hh6pb8h
    @user-mr1hh6pb8h Před 6 měsíci

    Bravo ❤

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Thanks for watching ❤️

  • @b3rn4rd01
    @b3rn4rd01 Před 7 měsíci +1

    ❤❤❤❤❤❤

  • @josesosa181990
    @josesosa181990 Před 5 měsíci

    Fella your are doing the Lord's work.

    • @MyDFIR
      @MyDFIR  Před 5 měsíci

      Thanks for watching!

  • @F3f33f
    @F3f33f Před 6 měsíci

    Legend!

  • @mapletech_22
    @mapletech_22 Před 6 měsíci

    This is awesome. 🎉🎉

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Thanks! Hopefully you learned something new ❤️

    • @mapletech_22
      @mapletech_22 Před 6 měsíci

      @MyDFIR sure. I learnt a lot. I graduated this year with a degree in cybersecurity, and the information you shared helped a lot.

  • @musicalprodigy1
    @musicalprodigy1 Před 7 měsíci +1

    In your description, the last word in the 4th line should read "are".
    Great content, well made and informative. Thanks
    Also, some of your scenes are blank, so the examples aren't clear.

    • @MyDFIR
      @MyDFIR  Před 7 měsíci

      Appreciate it and thank you for watching!
      Thanks for catching that error in my description, I just fixed it. Could you also provide me with an example about the scenes being blank? I would like to fix that as well.

  • @stanleyzogli5695
    @stanleyzogli5695 Před 6 měsíci

    MyDFIR, please can you make a detailed video with demo on True positive, false positive in EDR? Thanks

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Great suggestion! I’ll add it to the list.

  • @TheLogan1186
    @TheLogan1186 Před 5 měsíci

    Hey man really nice work and insight. I’m completely new to CS. Is there anything I can check out as a pre req to this video to have a better comprehension of this material. Thanks again

    • @MyDFIR
      @MyDFIR  Před 5 měsíci +1

      Thank you! Absolutely, there is a free course that ISC2 offers called Certified Cybersecurity. This is a great place to start. I’ve also created a video on where to start in Cybersecurity as well.
      www.isc2.org/certifications/cc
      Video: czcams.com/video/CAsuJaNg1xE/video.html
      Hope that helps!

    • @TheLogan1186
      @TheLogan1186 Před 4 měsíci

      @@MyDFIR thank you 🙏 🙏

  • @user-he2np4yf4q
    @user-he2np4yf4q Před 2 měsíci

    Thank you for the video and all you are offering. I come from a Non-technical background and recently completed a SOC certification. I am preparing for my 1st SOC interview. Could you please advise on how to prepare regarding Real Time Scenario interview questions, since I have no hands on experience!! Thank you!!

    • @MyDFIR
      @MyDFIR  Před 2 měsíci

      Congratulations on getting that interview! take a look at this video to help you prepare.
      czcams.com/video/E3Un5a-BPbc/video.html

    • @user-he2np4yf4q
      @user-he2np4yf4q Před 2 měsíci

      @@MyDFIR Thank you :)

  • @yeshichophel5428
    @yeshichophel5428 Před 3 měsíci

    damn its pretty good content !

  • @CurlyQ97
    @CurlyQ97 Před 5 měsíci

    I loved this video!! I did run into an issue with the Security Onion in the VM...when I run the VM, it tells me I need at least 99 GB of storage. That seems almost impossible. Is there something I am doing wrong since the 16 GB was not enough?

    • @MyDFIR
      @MyDFIR  Před 5 měsíci +1

      You may need to adjust the disk space to meet the requirement. I dont think you are doing anything wrong, just Security Onion does require more resources as it comes with a bunch of tools built in.

  • @Maha-rm3oy
    @Maha-rm3oy Před 5 měsíci

    Great, Thank you!
    I've just graduated and I will start my first job as SOC Analyst L1 in couple days and I only know the basics of using Linux.... am I in trouble ?

    • @MyDFIR
      @MyDFIR  Před 5 měsíci +1

      It’s going to be rough but as long as you keep learning and ask questions, you should be OK. Up to you but I would dedicate some time after work for self studying and complete hands on labs to level up my skills. This should translate to your job making you a better analyst.

  • @Tech-nicallyBlack
    @Tech-nicallyBlack Před 3 měsíci

    Great course! I ran into trouble with the ip address and gateway, do I use my own?

    • @MyDFIR
      @MyDFIR  Před 3 měsíci +1

      Thanks! I am assuming you are talking about setting up Security Onion and for that, you can set the network to NAT and it should grab the IP and gateway automatically.

    • @Tech-nicallyBlack
      @Tech-nicallyBlack Před 3 měsíci

      @@MyDFIR I used hyper V and set it to external but it didn't grab it, I'll try it again later. Thank you!

  • @pankajg9348
    @pankajg9348 Před 4 měsíci

    Hey, thanks for the valuable content!
    Can we set up the SecurityOnion environment shown in the above video in virtual box on Macs with Apple silicon?
    Will it run without any issues (because it's not Intel based Mac)?
    Thanks in advance!

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      I don't believe you can spin this up using Apple silicon unfortunately. If you would like to gain some hands on experience, you can think about using the cloud as an alternative.

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      @@MyDFIR Thanks for the quick response! Do you have any tutorial on how to use the cloud for this purpose?

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      Not specifically this but I have a video on how I spin up a VM in the cloud. You can do something similar.
      @15:16
      SOC Automation Project (Home Lab) | Part 2
      czcams.com/video/YxpUx0czgx4/video.html

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      Got it. Thanks!@@MyDFIR

  • @dancingkidkul9325
    @dancingkidkul9325 Před 6 měsíci

    Hey @MyDFIR,
    Does SOC Analyst should know the MITRE ATT&CK Framework or what because I talked many SOC analysts and they are not aware about it and whether it is for them or not?
    So can you make a video on it so as SOC analysts what all things they needs to know from MITRE ATT&CK Framework?

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +2

      YES. They should know the MITRE ATT&CK. This is what I am talking about, many analysts unfortunately are not aware of many things thus providing clients with 0 value in their escalations and it is NOT their fault. You don’t know what you don’t know.
      I am trying to shift this and train new or existing soc analysts to get to that next level. Don’t become those analysts who just copy and paste and hope for the best.
      I’ve created a video on MITRE here: czcams.com/video/b37r3d_LnvM/video.htmlfeature=shared

    • @dancingkidkul9325
      @dancingkidkul9325 Před 6 měsíci

      @@MyDFIR Thanks for reply here. Appreciate that

  • @triumphant_54
    @triumphant_54 Před měsícem

    Hi Steven, can someone who is trying to get into the filed focus on forensic as their first job?

    • @MyDFIR
      @MyDFIR  Před měsícem

      If say anything is “possible” but is it likely? Prob not but if forensics is what you want to do, I would think about what kind of forensics you want to get into and learn as much as possible.

    • @triumphant_54
      @triumphant_54 Před měsícem

      @@MyDFIR for now, i want to get good @ window forensic before focusing on linux .

  • @EvelynRobert-rs5br
    @EvelynRobert-rs5br Před 3 měsíci

    Hey my verification brought up different SHA256, it seems it was tampered with. What should I do?

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      Try re-downloading it, due to Security Onion being a large file, it has a risk of corruption during downloads which can alter the hash. I've seen this happen a couple of times.

  • @vasanthakumar525
    @vasanthakumar525 Před 6 měsíci

    Where can we master and practice soc skills? Like hack the box which will be good?

    • @dancingkidkul9325
      @dancingkidkul9325 Před 6 měsíci

      You can create labs in the cloud if you don't have devices and by using other different tools

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      This right here! But any simulated training is good - I personally use cyberdefenders & blue team level one.

    • @vasanthakumar525
      @vasanthakumar525 Před 6 měsíci

      @@MyDFIR thank you

  • @pankajg9348
    @pankajg9348 Před 4 měsíci

    Hey, when I am going through the Security Onion Setup, it says:
    "This machine currently has 1 NIC, but needs 2 to meet minimum requirements. Select OK to exit setup and reconfigure the machine."
    But, when I was setting up the VM in virtualbox, I followed all the instructions exactly as you mentioned (except for RAM and storage). There wasn't any option in the virtualbox setup to select the number of NICs. IDK why I got this error. Confusing. This error showed up after the step @30:34.
    Please help

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      You will be required to add an additional NIC - wiki.dave.eu/index.php/VirtualBox_Network_Configuration

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      @@MyDFIR Got it. Thanks!

  • @diegomed3364
    @diegomed3364 Před 6 měsíci

    What mini computer do you recommend to get to run efficiently security onion? I gotk 16 base memory it can t run security onion. I am using : Beelink Mini PC AMD Ryzen 7 5800H,Mini Desktop Computers 32GB DDR4/500GB M.2

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Odd, that should be enough to run Security Onion for a lab - Is it giving you errors? If so, what is it saying?

    • @diegomed3364
      @diegomed3364 Před 6 měsíci

      @@MyDFIR it said no enough memory. You need 16GB of memory.

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      @@diegomed3364I thought you have 32 GB RAM or I am misinterpreting your comment. From their documentation "In a standalone deployment, the manager components and the sensor components all run on a single box, therefore, your hardware requirements will reflect that. You’ll need at minimum 16GB RAM, 4 CPU cores, and 200GB storage. At the bare minimum of 16GB RAM, you will need swap space to avoid issues. We recommend a minimum of 24GB of RAM if you plan on monitoring traffic. The more traffic you plan on monitoring this RAM requirement will also increase."

    • @diegomed3364
      @diegomed3364 Před 6 měsíci

      @@MyDFIR it worked!!! I just had to update my and change RAM to 64

  • @TimCummingsFatLoss
    @TimCummingsFatLoss Před měsícem

    Go straight to security + or network?

    • @MyDFIR
      @MyDFIR  Před měsícem

      Depending on your networking skills, if its lacking id go for network first.

  • @soundsfromthebasement
    @soundsfromthebasement Před 6 měsíci

    Thanks so much for this, but i'm getting an error loading my VM. Can you help? it keeps saying aborted.

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Strange, have you moved the VM by any chance? If anything, try a clean install.

  • @Kimichi1
    @Kimichi1 Před 3 měsíci

    Hello, during the installation I kept getting the error "The IP being routed by Linux is not the IP address assigned to the management interface (enp0s3).
    This is not a supported configuration, please remediate and rerun. " I tried a lot of things but can't manage to solve this problem

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      Please take a look here: github.com/Security-Onion-Solutions/securityonion/discussions/2441

  • @tone396
    @tone396 Před 6 měsíci

    in the SO setup i get a message the says "the machine currently has 1 NIC but needs 2 to meet minimum requirements. and it tell me to exit setup to reconfigure the machine.

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      On your VM try adding another NIC to it and restart the setup

    • @tone396
      @tone396 Před 6 měsíci

      @@MyDFIR ok that worked then i got an error message saying currently the this machinee had 10. GB memenry but needs 16 to meet requirements

    • @tone396
      @tone396 Před 6 měsíci

      @MyDFIR i dont have the option to put more memory it limits me to 10. Is this from the host? cuz this has 16. im confused as to what is happening

  • @sincedayjuan
    @sincedayjuan Před 2 měsíci

    how sad, the sample pcap is not available anymore...

    • @MyDFIR
      @MyDFIR  Před 2 měsíci

      Hmmm It appears its all compiled under archive but if you don’t want to download GBs of pcaps, you can use any other pcap as the concept still applies. Let me know if you have any questions!

  • @vitache1276
    @vitache1276 Před 6 měsíci

    Do you offer trainings

    • @MyDFIR
      @MyDFIR  Před 6 měsíci +1

      Coming soon! But for now you can check out my products that I’ve created and the free videos on my channel ❤️

  • @dsiisus
    @dsiisus Před 6 měsíci

    I downloaded the latest SecurityOnion 2.4.30-20231219. I use Oracle VirtualBox for installation and I choose Standalone version, almost all minimum requirements are met (16GB Ram, 4 Cores, 200GB HDD and only one NIC, unfortunately it wont let me continue because I have only one NIC. Any solutions?

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      you can simply add a logical NIC card and that should satisfy the requirement

    • @dsiisus
      @dsiisus Před 6 měsíci +1

      @@MyDFIR I got it sorted but installation didn't work.

  • @jarrettseymore7805
    @jarrettseymore7805 Před 6 měsíci

    Do you have a paid Version on Udemy ?

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Great question - I do not, is there anything specific you might be looking for?

  • @ThorsdaleNigeriaLtd
    @ThorsdaleNigeriaLtd Před 6 měsíci

    Doesnt allow me use 8GB for Memory

    • @MyDFIR
      @MyDFIR  Před 6 měsíci

      Interesting, what does the error say?

  • @nevoh4940
    @nevoh4940 Před 3 měsíci

    I dont know if soc analyst will suit me

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      It definitely is not for everyone and can be pretty stressful.

  • @pankajg9348
    @pankajg9348 Před 4 měsíci

    Hey, this time it says:
    “This machine currently has 14 GB memory, but needs 16 GB to meet minimum requirements.
    Select YES to continue anyway, or select NO to cancel.”
    I selected YES and then this showed up:
    “This install type will fail with less than 16 GB of memory.
    Exiting setup.”
    I assigned the maximum amount of memory I could (my laptop has only 16 GB of RAM). And I assigned 4 processor cores.
    How do I solve this? Please help.

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      What have you tried so far? Have you tried researching how to solve this? You might need to select a different security onion option if you do not meet the minimum requirements.

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      I googled it but couldn't find anything useful. By "different security onion option" do you mean a different version of security onion? An older version? @@MyDFIR

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      @@MyDFIR I googled it but couldn't find anything useful. By "different security onion option" do you mean a different version of security onion? An older version? (Actually, I replied to your comment 3 days ago, soon after your reply but IDK why it isn't visible now. Hence, replying again.)

    • @MyDFIR
      @MyDFIR  Před 4 měsíci

      @@pankajg9348 Take a look at the documentation: docs.securityonion.net/en/2.4/hardware.html#cpu-architecture - I mean different as in try using Eval rather than standalone. If that fails, you can always try spinning this up in the cloud using free credits!

    • @pankajg9348
      @pankajg9348 Před 4 měsíci

      Oh! Got it. Thanks!@@MyDFIR

  • @cedrickmuluhh5793
    @cedrickmuluhh5793 Před 3 měsíci

    How can i contact you?

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      Via DM on socials or email if you sign up on my site.

  • @oliviangwa3473
    @oliviangwa3473 Před měsícem

    Hi Sir, how can I sign up for your free Mentorship Program 🙏🏽🙏🏽

    • @MyDFIR
      @MyDFIR  Před měsícem

      You can sign up via my site however there is a backlog currently

  • @zanekoh3473
    @zanekoh3473 Před 4 měsíci +2

    Is it too late to get into cybersec at age 30?

    • @MyDFIR
      @MyDFIR  Před 4 měsíci +3

      Not at all, you can definitely get in 🙌 Do expect to take 1.5-2 years though depending on your experience. (More towards the 2 year mark)

  • @shadrachwilson1211
    @shadrachwilson1211 Před 5 měsíci

    Wow! This is an in-depth video. I’ve got a lot to learn. Thank you for this Sir 🫡

    • @MyDFIR
      @MyDFIR  Před 5 měsíci

      Glad you enjoyed it!

  • @scuffedjays3862
    @scuffedjays3862 Před 3 měsíci

    Great video. I would just add SOC analysts should learn how to use modern EDRs.

    • @MyDFIR
      @MyDFIR  Před 3 měsíci

      Absolutely! 💯