This is the audio podcast version of Troy Hunt's weekly update video published here: https://www.troyhunt.com/tag/weekly-update/
…
continue reading
Sisällön tarjoaa Anton Chuvakin. Anton Chuvakin tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.
Player FM - Podcast-sovellus
Siirry offline-tilaan Player FM avulla!
Siirry offline-tilaan Player FM avulla!
EP202 Beyond Tiered SOCs: Detection as Code and the Rise of Response Engineering
MP3•Jakson koti
Manage episode 454643868 series 2892548
Sisällön tarjoaa Anton Chuvakin. Anton Chuvakin tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.
Guest:
Amine Besson, Tech Lead on Detection Engineering, Behemoth Cyberdefence
Topics:
- What is your best advice on detection engineering to organizations who don’t want to engineer anything in security?
- What is the state of art when it comes to SOC ? Who is doing well? What on Earth is a fusion center?
- Why classic “tiered SOCs” fall flat when dealing with modern threats?
- Let’s focus on a correct definition of detection as code. Can you provide yours?
- Detection x response engineering - is there a thing called “response engineering”? Should there be?
- What are your lessons learned to fuse intel, detections, and hunting ops?
- What is this SIEMless yet SOARful detection architecture?
- What’s next with OpenTIDE 2.0?
Resources:
- Guide your SOC Leaders to More Engineering Wisdom for Detection (Part 9) and other parts linked there
- Hack.lu 2023: TIDeMEC : A Detection Engineering Platform Homegrown At The EC video
- OpenTIDE · GitLab
- OpenTIDE 1.0 Release blog
- SpectreOps blog series ‘on detection’
- Does your SOC have NOC DNA? presentation
- Kill SOC Toil, Do SOC Eng blog (tame version)
- The original ASO paper (2021, still epic!)
- Behind the Scenes with Red Canary's Detection Engineering Team
- The DFIR Report – Real Intrusions by Real Attackers, The Truth Behind the Intrusion
- Site Reliability Engineering (SRE) | Google Cloud
212 jaksoa
MP3•Jakson koti
Manage episode 454643868 series 2892548
Sisällön tarjoaa Anton Chuvakin. Anton Chuvakin tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.
Guest:
Amine Besson, Tech Lead on Detection Engineering, Behemoth Cyberdefence
Topics:
- What is your best advice on detection engineering to organizations who don’t want to engineer anything in security?
- What is the state of art when it comes to SOC ? Who is doing well? What on Earth is a fusion center?
- Why classic “tiered SOCs” fall flat when dealing with modern threats?
- Let’s focus on a correct definition of detection as code. Can you provide yours?
- Detection x response engineering - is there a thing called “response engineering”? Should there be?
- What are your lessons learned to fuse intel, detections, and hunting ops?
- What is this SIEMless yet SOARful detection architecture?
- What’s next with OpenTIDE 2.0?
Resources:
- Guide your SOC Leaders to More Engineering Wisdom for Detection (Part 9) and other parts linked there
- Hack.lu 2023: TIDeMEC : A Detection Engineering Platform Homegrown At The EC video
- OpenTIDE · GitLab
- OpenTIDE 1.0 Release blog
- SpectreOps blog series ‘on detection’
- Does your SOC have NOC DNA? presentation
- Kill SOC Toil, Do SOC Eng blog (tame version)
- The original ASO paper (2021, still epic!)
- Behind the Scenes with Red Canary's Detection Engineering Team
- The DFIR Report – Real Intrusions by Real Attackers, The Truth Behind the Intrusion
- Site Reliability Engineering (SRE) | Google Cloud
212 jaksoa
Kaikki jaksot
×Tervetuloa Player FM:n!
Player FM skannaa verkkoa löytääkseen korkealaatuisia podcasteja, joista voit nauttia juuri nyt. Se on paras podcast-sovellus ja toimii Androidilla, iPhonela, ja verkossa. Rekisteröidy sykronoidaksesi tilaukset laitteiden välillä.