Detection at Scale

Meta's Justin Anderson on How to Understand, Identify, and Execute Your Detection Strategy


Listen Later

On this week's episode of the Detection at Scale podcast, Jack talks with Justin Anderson, Security Engineering Manager, Detection & Response at Meta. They discuss how Meta has built its detection engineering program, how it treats detection-as-code like software, and how it gauges risk by assessing the TTPs applicable to the environment. They also talk about where AI is able to help out in development, the greater need for engineering and investigation skills, and three things to remember when building a security program.

Topics discussed:

  • How Meta gauges risk by assessing the TTPs applicable to the environment and measuring coverage across those TTPs.
  • How they built out their detection platform on a custom infrastructure and treat detection-as-code like software.
  • Why they take a shift left approach to detection, starting with TTPs hypotheses and then eliminating as much noise as possible.
  • How taking a page from the vulnerability management playbook helps reduce noise around detections.
  • AI’s current limitations in detection and response, yet how it helps with writing code and speeding up development times.
  • Why there's a greater need for stronger engineering and investigation skills, in addition to coding skills.
  • Advice to security professionals to focus on understanding, identifying, and executing when building out their program. 
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,966 Listeners

    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    367 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,014 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    314 Listeners

    Click Here by Recorded Future News

    Click Here

    392 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    313 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    352 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    118 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,037 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners

    No Priors: Artificial Intelligence | Technology | Startups by Conviction

    No Priors: Artificial Intelligence | Technology | Startups

    129 Listeners