Talk With an Expert

Practical El Jefe

Practical El Jefe (PDF, 5.24MB)Published: 31 Mar, 2015
Created by:
Charles Vedaa

El Jefe is open source process monitoring software for Windows. With this tool, incident handlers gain insight into all processes running on hosts with the El Jefe agent. The agent logs each process's path, checksum, and parent process information to a central server. From this server, responders can identify unusual binaries, or suspicious process relationships, and instruct the agents to fetch files for further analysis. This paper will review the setup of the El Jefe server and deployment of the agents. From there, the paper will explore common use cases for an incident handler and examine the evidence gathered from simulated intrusions.