Remove author roberto
article thumbnail

Sysmon Security Event Processing in Real Time with KSQL and HELK

Confluent

Roberto Rodriguez is a senior threat hunter and researcher at SpecterOps, where he specializes in the development of data analytics to detect advanced adversarial techniques. He is also the author of several open source projects, such as the Threat Hunter Playbook and HELK. . Real-Time Sysmon Processing via KSQL and HELK?—?Part

Process 80