Detection Engineering in Gravwell

Logo
Presented by

Gravwell

About this talk

The purpose of this video is to showcase Gravwell’s search capabilities through a slightly different lens than those of previous videos: that of a detection engineer. While we are building on findings from our previous videos in this series, our objectives have shifted; namely, we are aiming to develop queries that will allow us to discover threat actor activity on a proactive basis. In support of this goal we will not be focusing expressly on query logic but rather on the findings surfaced via said queries. We will then transition to the Automation “Flows’ functionality to show how a query can be translated to an automated notification using no-code workflows.
Related topics:

More from this channel

Upcoming talks (1)
On-demand talks (11)
Subscribers (1048)
Gravwell is a data platform with security lake features that enables teams to investigate, collaborate, and analyze data on-demand, from any source — all with unlimited data collection and retention.