InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Detection Technique Deep Dive

Presented by

Doug Brown - Senior Threat Hunter at CrowdStrike

About this talk

Having detection techniques at hand – which you can apply in systematic approaches across different environments – is a ninja skill detection engineers and threat hunters need to have. In this session, Senior Threat Hunter Doug Brown will provide you with just that. Join Doug as he explores a range of concrete search techniques to measure a variety of behavioural changes, and demonstrates how to map those to MITRE ATT&CK techniques. Attend this session to learn how to: Map advanced statistics to MITRE ATT&CK techniques Detect spikes with median absolute deviation and handle data with seasonality Identify first-time events in new values seen in a field or combination of fields, including cardinality of distinct fields to measure behaviour change Detect C2 beaconing through domain parking and lateral movement with RDP for first-time users by applying simple sequencing techniques Plus, you’ll get bonus examples of highly complex sequencing approaches.
Splunk Inc.

Splunk Inc.

42890 subscribers338 talks
Splunk Webinars and Videos
Splunk is helping to build a safer and more resilient digital world by equipping customers with the unified security and observability platform they need to keep their organization securely up and running — no matter what digital disruptions come their way.
Related topics