Slide 31
Slide 31 text
Matching on forensic telemetry
Process execuHon, file
events, network connecHons,
registry changes
Preserves historical data,
short-lived events
Expensive to centralize in
large environments
Limited scope of data for IOC
matching
31
Workstations Servers
Historical Activity
(Telemetry, logs, alerts,
historical data)
EXE
Current Activity
(Processes, Network
Connections, Memory)
Data at Rest
(Files on disk, registry)