InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

The Scientific Method to Picking Apart a Detection

Presented by

Raja Jasper, SOC Manager at a financial institution and Saurabh Wadhwa, a Senior Solutions Engineer at Uptycs

About this talk

In this session Raja Jasper, SOC Manager at a financial institution and Saurabh Wadhwa, a Senior Solutions Engineer at Uptycs, discuss how to use osquery and MITRE ATT&CK to build sophisticated detections based on behavior, rather than IOCs. Detections based on behaviors tell a story and provide analysts a lot more context, plus they are more troublesome for attackers to avoid. Osquery gathers the endpoint telemetry needed to build these types of detections. Raja and Saurabh demonstrate how to use osquery to build a behavior-based detection using Emotet malware as an example. Check out the other sessions from Osquery@scale, an annual event hosted by Uptycs for the osquery community. This event was held in San Francisco at the Exploratorium in September, 2022. Join us at future events to learn how security leaders and practitioners from Financial Services, Telco, SaaS, Hi-Tech, and other industries use osquery to manage security risks at scale.
Uptycs

Uptycs

943 subscribers37 talks
Learn how to shift up your cybersecurity.
Secure cloud, containers, and endpoints with one unified solution. Find and remove critical risks in your modern attack surface—from laptops to containers—all from a single UI and data model.
Related topics