SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsEl Jefe is open source process monitoring software for Windows. With this tool, incident handlers gain insight into all processes running on hosts with the El Jefe agent. The agent logs each process's path, checksum, and parent process information to a central server. From this server, responders can identify unusual binaries, or suspicious process relationships, and instruct the agents to fetch files for further analysis. This paper will review the setup of the El Jefe server and deployment of the agents. From there, the paper will explore common use cases for an incident handler and examine the evidence gathered from simulated intrusions.