Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Differentiating Evil from Benign in the Normally Abnormal World [Splunk Enterprise Security, Splunk IT Service Intelligence, Phantom]
    Have you ever been positive you had found evil, only to realize it was normal after hours of triage and work? We have all heard and love “KNOW NORMAL FIND EVIL,” but how hard is it to actually know normal? The MITRE ATT&CK Framework gives defenders a better map to “find evil,” but how can this framework be used to “know normal”?Rick will discuss how knowing normal in a world of abnormal is harder than one thinks, and how addressing the actual root cause of evil can improve the technology industry as a whole.

    Speaker(s)
    Rick McElroy, Principal Security Strategist , Carbon Black

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SECS2917.pdf?podcast=1577146215

    Product: Splunk Enterprise Security, Splunk IT Service Intelligence, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Diving into Splunk Phantom's Overlooked Features [Phantom]
    Whether you're a new or experienced Splunk Phantom user, you'll learn from the high-value, often overlooked features we discuss in this session. We'll showcase some of Phantom's most overlooked valuable features, as well as experienced users' top ranked features. Join us to learn more about how you can optimize your use of Splunk’s SOAR (Security Orchestration Automation & Response) platform.

    Speaker(s)
    Phil Royer, Research Engineer, Splunk
    Kavita Varadarajan, Product Manager - Phantom, Splunk
    Sam Hays, Sr. Technical Community Manager , Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1705.pdf?podcast=1577146215

    Product: Phantom

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Don't Blow Your Budget Fighting Fraud; Orchestrate and Automate Instead [Splunk Enterprise, Splunk Cloud, Phantom]
    Manual sorting through spreadsheets, disparate applications, and scattered data sources to conduct link analysis for a fraud investigation is both painful and ineffective. There must be a better way, right? In this session we'll use Splunk Enterprise and Splunk Phantom to automate repeatable fraud investigation tasks, which will save your team time and better protect your assets from the bad guys.

    Speaker(s)
    Matthew Joseff, Director of Specialists - North Asia and Japan, Splunk
    Abhishek Dujari, Security Specialist, APAC, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1104.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Cloud, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Down in the Weeds, Up in the Cloud: Security [Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security]
    This is one of multiple sessions in a series at .conf this year focused on getting valuable intel and insights from your Azure and Office 365 environments. Throw on your hoodie and join Ryan as we Splunk our way through all things Azure, Office365, security, compliance, and visibility in the Microsoft-as-a-Service world.

    Speaker(s)
    Ry Lait, Senior Sales Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1432.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Dude, Where’s My Log? The Unknown Logging Gaps in Your Environment, Why You Didn't Detect that Pentest, and How Splunk Can Help [Splunk Enterprise]
    Failure to log everything needed for maximum visibility in your environment can leave huge gaps in your ability to remediate threats. But running an enterprise-level logging program can be difficult: how do you know if you're logging everything necessary to detect threats? Are all of your technologies configured to send the right logs? Are they all logging to Splunk? In this session we will help you answer these and other critical questions of your logging program, which will ultimately help you remediate issues and better use log analysis to mitigate threats.

    Speaker(s)
    Kevin Kaminski, Threat Management R&D Lead, ReliaQuest

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2179.pdf?podcast=1577146215

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Enterprise Security Biology III: Dissecting the Incident Management Framework [Splunk Enterprise Security]
    Splunk's Incident Management Framework is used extensively in support of the notable event creation, and it serves as a bridge that associates the Risk, Asset & Identity, and Threat frameworks together. In this session we will discuss how incident management functions, what occurs behind the scenes to prepare events that are correlated, and how to present correlated events to analysts. Attendees will leave this talk with a greater understanding of the Incident Management Framework and methods to work more effectively with it within Splunk Enterprise Security.

    Speaker(s)
    John Stoner, Principal Security Strategist, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1544.pdf?podcast=1577146215

    Product: Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Enterprise Security for an Internet Service Provider: How Splunk Enterprise Security Changed the Way We Work and Changed the Organization [Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit]
    20+ million subscribers, 290PB network traffic daily, and tens of millions of IoT, IPTV and ICT devices—a bigger network means more attacks from all over the world. Learn how SK Broadband, the biggest telco/ISP provider in South Korea, leverages Splunk Enterprise Security (ES) to protect their subscribers from countless DDoS and malware attacks. We will cover detailed use cases for analyzing a high volume of data—500 million security events over 7 billion logs per day—as well as how we met a high bar of operational efficiency by customizing our ES deployment.

    Speaker(s)
    Daesoo Choi, Senior Sales Engineer, Splunk
    Kyoung Geun Lee, SoC Senior Manager, SK Broadband

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2274.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Machine Learning Toolkit

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Examining Splunk Phantom's Architecture [Phantom]
    Want to learn more about Splunk Phantom's platform architecture? Join us in this session for an in-depth technical review of all key processes, including ingestion, automation, action execution, health monitoring, the data store, and more. This session will give experienced users a much deeper understanding of the technology behind Splunk’s SOAR (Security Orchestration Automation & Response) platform.

    Speaker(s)
    Sourabh Sourabh, VP & Distinguished Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1709.pdf?podcast=1577146215

    Product: Phantom

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Feed the Beast! Use Splunk to Address APTs At Speed and Scale By Utilizing Endpoint-Centric Threat Hunting Uses Cases [Splunk Enterprise]
    Going beyond basic perimeter defense, Threat Hunting cuts through the noise of endpoint telemetry and anti-virus data to find nation-state level Advanced Persistent Threats (APTs) that hide below the alert threshold. We will demonstrate, through 4 hunt analytic use cases, how to overcome the legacy challenge of relying on Packet Capture (PCAP) data to detect adversaries, highlighting the need to transform Hunt operations by combining Endpoint Detection and Response (EDR) telemetry data with knowledge of APT behavior to find hidden adversaries. This talk will provide a framework for planning and executing hunts, demonstrate why focusing on EDR telemetry data can add additional value over and beyond traditional network data, and how to strengthen hunting through a Purple Team approach.

    Speaker(s)
    Max Moerles, Cyber Threat Analyst , Booz Allen Hamilton
    Jay Novak, Threat Hunt Team Lead, Booz Allen Hamilton

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1250.pdf?podcast=1577146215

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Finding Evil Is Never An Accident: How to Hunt in BOTS [Splunk Enterprise, Splunk Cloud]
    To secure the modern endpoint, you need sufficient data, the right visibility and analysis, and the technology necesary to stop an intrusion. We will leverage BOTSv4 data in this session to help you test and validate Splunk use cases related to hunting threats using endpoint data. We’ll cover several real world case studies as described in MITRE ATT&CK™, and we will simulate adversary groups by executing a single Atomic test and building an elaborate chain reaction. We will then show you in Splunk how to confirm your data quality and confirm you have what you need to detect and evict an adversary from your environment. We will demonstrate practical hunt techniques using BOTSv4 data and how to raise the flag when data is missing or is not required.

    Speaker(s)
    Michael Haag, Director of Advanced Threat Detection, Red Canary

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1952.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Cloud

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides