Bridging the Gap: Improving Rules Effectiveness by Integrating Detection and Response

preview_player
Показать описание
SANS Blue Team Summit 2023
Bridging the Gap: Improving Rules Effectivenessby Integrating Detection and Response
Speaker: Paul Hutelmyer, Principal Engineer, Target Corporation

As cyber threats continue to evolve and become more sophisticated, organizations are deploying an increasing number of detection rules to help identify these threats. However, the management of these rules and the assurance that your rule set does not result in excessive false positives can be a challenge. In this talk, we'll explore the concepts and tools Target uses to fuse detection rules and detection case results to better understand rule effectiveness, gaps, and scope. We'll also share our observations and ideas about content tagging and standards that can help improve the effectiveness of threat detection and response. By combining detection and response data, organizations can achieve better outcomes and stay ahead of evolving cyber threats.

Рекомендации по теме