Christopher Martin, Security Specialist, Google Cloud
Ever feel like your security team is overly reliant on vendor-created threat detection? There are nuances to your environment that often require a more customized approach to identifying potential TTPs. Furthermore, advanced threat actors may use methods, techniques and malware that are custom-made for your organization. The art of detection is evolving as more investments are made into SOC analysts, threat responders, and hunters - and as part of this movement, data driven detection is emerging as the most accurate way to craft enterprise-specific detections.
Attend this session to learn how you can intelligently transform your security strategy by authoring detections, treating them as code, and putting best practices in place to use, store, share and maintain your custom detections.
Learn how to get started with a custom detection security strategy.
Experience how the custom detection lifecycle provides insight into attacker behavior.
Understand the core components of authoring detections.
See how you can incorporate security frameworks into your detections.
Learn how a data driven approach to detection writing detections captures lessons learned and sustains institutional knowledge.