Security Secrets: The Art Of Agile Detection Engineering

Logo
Presented by

Patrick Bareiss, Senior Security Research Engineer, Splunk; Brandon Dunlap, Moderator

About this talk

One of the biggest challenges for security teams today is to keep up with modern adversaries. A SOC needs to continuously improve detection capabilities based on the evolving adversary techniques. The time between a new attack seen “in the wild” and deploying a new detection in your SIEM is crucial to success. SOC processes, especially detection development, need modernizing in order to keep up with the advancing threat landscape. This is where the agile DevOps mindset should be adopted within SOCs to reduce the detection development time. Join Splunk and (ISC)2 on September 29, 2020 at 1:00 p.m. BST as we explore: · DevOps and its advantages in a modern SOC · What modern detection development looks like using DevOps methods · How to build an automated workflow for validating and testing detection content · How to use Splunk open source Attack Range for embedding development and testing of detections
Related topics:

More from this channel

Upcoming talks (11)
On-demand talks (392)
Subscribers (93605)
ISC2 Security Briefings EMEA offers members in Europe, the Middle East and Africa a chance to learn about the latest trends, tools and best practices in cyber, information, software and infrastructure security while earning CPEs