Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Use Red Team Exercises to Build Alerts, Train Staff, and Drive Policies [Splunk Enterprise, Splunk Enterprise Security]
    Most of us have had (or still have) nightmares about an alert that someone's exfltrating data from our organization. We've lived that nightmare at Harris, and we've learned from it. In this session, we'll discuss how we used red and purple teaming to improve our security posture post-breach. Learn from our experience so that you can strengthen your team's alerting, staff comptency, and policies, and reduce the risk of a breach at your company.

    Speaker(s)
    Nate Piquette, Sr. Detection & Response Engineer, L3Harris Technologies
    Adam Parsons, Sr. Detection & Response Engineer, L3Harris Technologies

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1375.pdf?podcast=1577146216

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Use Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]
    Obtaining data to develop defenses against threats is a constant challenge for security analysts. To that end, Splunk's Security Research team developed the Splunk SIEMulator, a framework modeled after Chris Long's DetectionLab that allows a defender to replay attack scenarios using AttackIQ in a simulated environment. SIEMulator’s Attack Range environments are all configured with Splunk forwarders and the apps necessary to create and store data in CIM data models. We'll show you how to use the SIEMulator to produce shareable data that can help security analysts replicate scenarios and effectively detect, investigate, and respond to threats.

    Speaker(s)
    Phil Royer, Research Engineer, Splunk
    Rod Soto, Principal Security Research Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1671.pdf?podcast=1577146216

    Product: Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Using Machine Learning to Unlock the Potential of Your Security Data [Splunk Enterprise, Splunk Cloud]
    Vectra customers and security researchers respond to some of the world’s most consequential threats. And they tell us that there’s a consistent set of questions they must answer when investigating any attack scenario.Yet, security data today is broken and unable to effectively answer those questions. It is either incomplete or storage and performance intensive. Most teams don’t have the information necessary to properly answer the questions required to support their use cases; whether it be for threat hunting, investigations or supporting custom tools and models.In this session, hear about real-world use cases where security teams use machine learning engines to derive unique security attributes and how it is embedded into security workflows.

    Speaker(s)
    Kevin Sheu, Vectra

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2589.pdf?podcast=1577146216

    Product: Splunk Enterprise, Splunk Cloud

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Using Splunk and DNS to detect that your domains are being abused for phishing [Splunk Enterprise, Splunk Enterprise Security]
    As a high-profile public-sector organization, the Dutch Tax and Customs Administration deals with criminals claiming to be representatives of the organization and contacting the public with phishing e-mails every day. By using Splunk and RFC’s like, RFC7208 – Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, we have developed a technique to identify phishing attacks that are carried out under the disguise of the Dutch Tax and Customs Administration. This technique is universally applicable. A precondition is access to the DNS logging. By means of this technique, insight can be obtained where the phishing e-mails are sent from and to whom the phishing e-mails are sent. In this talk we will start by explaining which standards are available to increase e-mail security and how we have build an app in Splunk, including dashboard and a wizard to create the necessary DNS records to gain insight information about the abuse of our domains.

    Speaker(s)
    Karl Lovink, Lead Security Operations Center, Dutch Tax and Customs Administration
    Arnold Holzel, Senior Security Consultant, SMT

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1106.pdf?podcast=1577146216

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Using Splunk to Catch Theft Rings [Splunk Enterprise, Splunk Enterprise Security]
    We helped our client use Splunk to disrupt theft rings plaguing its retail stores. We'll present how we took in public wifi data, tracked MAC addresses that appeared in multiple stores, and ultimately created a system in Splunk that alerted in-store loss prevention teams when individuals likely to be involved in theft rings entered the store. We'll go over the steps taken to operationalize our theft deterrence program so that you can adopt it in your organization or modify it to fit your needs.

    Speaker(s)
    Nic Haag, Splunk Professional Services Consultant, Aditum Partners
    Logan Foshee, Threat Analyst, Lowe's

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1336.pdf?podcast=1577146216

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Walking the Talk for Diversity and Inclusion in Cybersecurity [Splunk Enterprise]
    We believe that to best defend against global security threats, an organization needs defenders who represent the diverse world that we live in. Every business will benefit greatly by bringing more people to the table with varying skills, backgrounds, leadership and views to combat the diverse adversaries out there. Here at Splunk, we have created initiatives like the "Developing Superwomen in Cybersecurity" program that works to diversify and equalize the cybersecurity workforce to women and other underrepresented groups. Come hear how we are taking action by making cybersecurity accessible to all with this program and some practical advice on how you can do the same when you go back to your organization! You'll receive tips on how to make information security inclusive to all with ways of engaging your staff at various levels and receive a blueprint for running your own gamified security experiences, allowing you to up-level staff while embracing their unique talents and backgrounds.

    Speaker(s)
    Kelly Kitagawa, Customer Success Manager, Splunk
    Lily Lee, Staff Security Specialist, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SECD2004.pdf?podcast=1577146216

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Catch exfiltration from cloud file stores early! [Splunk Enterprise, Splunk Enterprise Security, Splunk User Behavior Analytics]
    In this session, we tackle data breaches and information exfiltration from cloud file stores. Beyond the attacks that make headlines and result in millions of stolen personal records, we will also focus on the far less publicized risks related to exposure of intellectual property, infrastructure details or finances. We will share our experience in building a defensive strategy that now detects highly-covert exfiltration attempts.To this end, we first shed a lot of light on how companies use general-purpose file stores, such as Box, Office365 or Google Drive. We cover the types of files that commonly get stored in the cloud, file sharing practices, access properties, as well as uses of cloud stores by various departments. There are a lot of unexpected insights which eventually invalidate common security assumptions.As the boundary between good and bad gets blurred, we will provide you with a peek into how to design an effective data-driven defense. This approach helped us hone our detection to just tens of validly suspicious exfiltration files in a massive cloud store.

    Speaker(s)
    Stanislav Miskovic, Security Data Science, Splunk
    Ignacio Bermudez Corrales, Senior Data Scientist, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2083.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk User Behavior Analytics

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Defense Against the Dark Arts: Splunk Edition [Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML]
    Malware infection, lateral movement, data exfiltration, oh my! If you’ve spent any time around the wizarding world of security, you know how much effort goes into preventing dark magic from happening. What if you could use machine learning to stay one step ahead of the adversary? Fasten your seatbelts, because in this talk we will show you how Splunk can utilize machine learning models to take your security detections to the next level. We’ll demonstrate how Splunk's Machine Learning Toolkit can be used to train, validate, and then deploy models to identify anomalies and discover clusters of bad behavior via user-friendly guided workflows—all this while training your models with more data then you’ve ever been able to before. Prepare to leave Las Vegas equipped to incorporate machine learning in your organization’s security detections and jump from reactive to proactive. Mischief managed!

    Speaker(s)
    Melisa Napoles, Sales Engineer, Splunk
    Erika Strano, Sales Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2129.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Deploying Splunk Enterprise Security and Splunk Phantom At Scale [Splunk Enterprise, Splunk Enterprise Security, Phantom]
    Ever wondered how to integrate or scale Splunk Enterprise Security (ES) and Splunk Phantom? Join us as we explore best practices involved in setting up clustered environments for ES and Phantom that yield a highly available and scalable security platform. You will leave this session better able to create scalable ES and Phantom deployments, tools, commands, cheat sheets, and troubleshooting methods at your own organizations.

    Speaker(s)
    Mayur Pipaliya, Forward Deployed Software Engineer, Splunk
    Ankit Bhagat, Forward Deployed Software Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2233.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Detect and Mitigate Insider Threats Using Splunk's Machine Learning Toolkit and Splunk Enterprise Security [Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML]
    When is a 20MB email to an external Gmail account dangerous? It all depends on context. Understanding what normal behavior is will reveal whether specific behavior is malicious or ordinary. We’ll walk you through how using Splunk’s Machine Learning Toolkit and Splunk Enterprise Security together provides actionable insight for analysts to improve security. We'll also detail how we caught insider threats in our environment with these tools.

    Speaker(s)
    Karthik Subramanian, Principal Senior Cybersecurity Engineer, SAIC
    Tyler Williams, Cybersecurity Data Analyst, SAIC

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1305.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides