Threat hunting with Scored network features

BSides MSP 2017

Presented by: Justin Warner
Date: Sunday June 25, 2017
Time: 13:30 - 14:15
Location: Track 1

Most organizations collect mountains of network data from across their enterprise but few actually take a look behind the curtain that is their SIEM dashboard. Shifting from a reactive approach to a more proactive methodology is essential to detect increasingly clever adversaries and advanced threats. But with so much data, where do we start? This talk will present an introduction to big data analysis techniques and threat hunting, specifically focusing on extracted network features. It will span the process of contextualization, enrichment, and finally analysis. These concepts will be applied by telling a fun for all ages story of a "fictitious" threat detection and response scenario involving Mickey Mouse and friends.

Justin Warner


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats