InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

How National Grid gains rich attacker insight from Threat Response alerts

Presented by

Frank Furlo, Principal CSIRT Analyst, National Grid and Scott McCarthy, Senior SOAR Engineer, National Grid

About this talk

Alert fatigue and desensitization, high false-positives, confirmation bias...sound familiar? One-for-one alerting models come with a lengthy list of cons compared to pros. For National Grid’s CSIRT team, too many questions were left unanswered. It was time for a more in-depth analysis of their attack surface. Leveraging their Tanium instance and the ‘Tanium MITRE Rule,’ they were able to apply additional correlation logic that reduced false positives, increased alert abilities, and get the most out of the telemetry coming from Tanium. Watch this short presentation to learn more.
Tanium

Tanium

11181 subscribers110 talks
Tanium Autonomous Endpoint Management (AEM)
Tanium Autonomous Endpoint Management (AEM) offers the most comprehensive solution for intelligently managing endpoints across industries, providing capabilities for asset discovery and inventory, endpoint management, vulnerability management, risk and compliance, threat hunting & incident response, and digital employee experience. The platform supports 34M endpoints worldwide, including 40% of the Fortune 100, delivering increasingly efficient operations and an improved security posture at scale, with confidence, and in real time.
Related topics