Weâll be hearing from three vendors in this edition of Oilers. Dino Dai Zovi will be along first up to talk about his startup, Capsule8, which looks very promising indeed.
After weâve heard from Dino weâll be chatting with Chris McNab. He used to run incident response for iSec Partners and later NCC Group, but these days he runs AlphaSOC, a company he founded. Theyâre a very simply play â they do DNS and IP analytics.
They offer that as a Splunk application or via an API, and you would be amazed how much bad stuff you can kick off your network with something as simple as DNS and IP analytics. Tor exfil, whole families of malware, BitTorrent, all sorts of stuff. Chris will be along soon to talk about that.
Then weâre rounding it out with a conversation with Sylvain Gil, the co-founder of Exabeam.
Exabeam started off in analytics and UEBA, but theyâve taken a bunch of money and theyâre spending it on building out their SIEM, which is already pretty popular in certain circles because they donât license it based on volume. Sylvain pops along later on to talk about how thatâs changing SIEM use cases for a bunch of people. For example they can pump their EDR logs into their SIEM without wearing a seven figure SIEM consumption bill. He also walks through how theyâve used open source technologies like Hadoop in their products. Itâs an all around chat that one, not so much a pitch, but yeah, I found it really interesting and I hope you will too.
Links to all three profiled vendors are below!