Detection at Scale

Elastic’s Darren LaCasse on Cutting Alert Volumes in Half By Automating Responses


Listen Later

In this episode of Detection at Scale, Jack Naglieri chats with Darren LaCasse, Director of Threat Intelligence, Incident Response, & Threat Detection at Elastic. Darren offers insights into the innovative project around detection as code, shedding light on the methodologies Elastic employs to enhance security operations. 

Darren touches on the challenges of managing massive amounts of data, the importance of prioritization in security tasks, and how automation has revolutionized their response strategies. He also shares practical advice on conducting gap analyses to focus on what truly matters. 

 

Topics discussed:

  • The importance of prioritizing security tasks to focus on critical business-impacting elements, ensuring a resilient security framework.
  • Strategies for handling and analyzing large volumes of security data to maintain effective monitoring and response capabilities.
  • How automation has halved alert volumes, freeing analysts from repetitive tasks and enhancing overall productivity.
  • Conducting regular gap analyses and attack path discussions to visualize vulnerabilities and direct security efforts effectively.
  • The role of tagging and context-aware responses in streamlining security operations and making analysts' lives easier.
  • Prioritizing security efforts based on the criticality of vendors and data, focusing first on restricted and critical vendors.
  • The importance of conducting at least annual reviews to reassess and improve security controls and monitoring strategies.
  • Using metrics to measure the effectiveness of security measures and guide continuous improvement efforts.
  •  

    Resources Mentioned: 

    • Darren LaCasse on LinkedIn
  • Elastic Security Solution website
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Risky Business by Patrick Gray

    Risky Business

    374 Listeners

    SpyCast by SpyCast

    SpyCast

    1,535 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    653 Listeners

    The Defender's Advantage Podcast by Mandiant

    The Defender's Advantage Podcast

    33 Listeners

    Science Vs by Spotify Studios

    Science Vs

    12,225 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    318 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,039 Listeners

    All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

    All-In with Chamath, Jason, Sacks & Friedberg

    9,927 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    511 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    138 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    44 Listeners

    The Economics of Everyday Things by Freakonomics Network & Zachary Crockett

    The Economics of Everyday Things

    1,654 Listeners

    Prof G Markets by Vox Media Podcast Network

    Prof G Markets

    1,427 Listeners

    Sources & Methods by NPR

    Sources & Methods

    798 Listeners