Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Getting Started with Risk-Based Alerting and MITRE [Splunk Enterprise, Splunk Enterprise Security]
    Risk-based alerting is gaining traction in the SOC: by using multiple-lower fidelity searches to yield higher-fidelity investigations, it allows analysts to rapidly prioritize investigations, correlate “risk objects” between alerts, identify gaps in monitoring, and generally understand attack narratives. We'll discuss the first steps needed to transition from the traditional one-to-one ticket investigation model to this holistic approach, i.e. how risk-based alerting works, a description of prerequisites, and dashboard optimization. We will also discuss how to start building a comprehensive search inventory based on Splunk analytics, MITRE, and your own threat intelligence.

    Speaker(s)
    Bryan Turner, IT Security Analyst, Publix Super Markets

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1538.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Have No Fear, WMI Is Here: Identify Lateral Movement and Malicious Backdoors with Windows Management Instrumentation [Splunk Enterprise, Splunk Enterprise Security]
    Attackers are increasingly using a 'living off the land' approach, often using crypto mining malware, EternalBlue, timing, or other attacks that leverage the Windows Management Instrumentation Command Line. These attacks typically don't generate any events via conventional Sysmon and PowerShell, so even if you're pulling in those logs you likely won't see them. Join this session to learn how to detect and protect your organization from these advanced WMI-based attacks.

    Speaker(s)
    Ryan Becwar, Sales Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1550.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • How We Scaled Splunk Enterprise Security to 100TB with Search Head Clustering [Splunk Enterprise Security]
    Want to scale Splunk Enterprise Security to 100TB/day? We've done it! In Splunk labs, we built workloads that closely simulate our customers' usage patterns, and we scaled beyond a 100TB per day ingest rate with search head clustering. In this session we'll share key aspects of our Splunk Enterprise Security workload design: diverse source types, major data models, search scenarios, data enrichment, and hardware choices for search head and indexer. We will also share how different configurations impact search performance and how to tune Splunk Enterprise Security effectively with parameters such as max_searches_per_cpu, acceleration.max_concurrent, allow_skew, and maxBundleSize to name a few. Come see how we scaled to large volumes while efficiently utilizing hardware capacity for maximum performance.

    Speaker(s)
    Devendra Badhani, Sr Engineering Manager, Splunk
    Jesse Chen, Principal Performance Engineer, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1554.pdf?podcast=1577146215

    Product: Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Hunting in the Dark: Profiling Encrypted Network Traffic [Splunk Enterprise]
    It's not easy to detect malicious patterns within encrypted network traffic. JA3, a method of fingerprinting Secure Sockets Layer (SSL) traffic developed by SalesForce, aims to address this by profiling client (JA3) and server (JA3s) SSL connections. Since these fingerprints are unique and persistent, they provide a way to discover applications, fingerprint Operating Systems, and even discover malware. This presentation showcases how to use Splunk to streamline JA3 event data gathered from Bro/Zeek, use that in combination with host-level visibility provided by Carbon Black, and ultimately correlate network signatures with endpoint telemetry. You will learn how to use this method to get a better understanding of what processes are causing benign or malicious SSL connections on your network and how to hunt for unknown threats.

    Speaker(s)
    Mike Sconzo, Staff Threat Intel Engineer, Box
    Jayson Weiss, Security Engineer III, Box

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2056.pdf?podcast=1577146215

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • I Have Authority to Operate in the Cloud...Now How Do I Secure It? [Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security]
    You finally got Authority To Operate (ATO) in the Cloud, and you're feeling the budgetary and political pressure to transition your workloads to AWS. But how do you actually transition a workload securely? This session covers the essentials of using Splunk to quickly increase your security posture and awareness in the Cloud. Learn from our experiences and leave with more confidence that you're asking smart questions of your data, monitoring and alerting on the right things, assigning responsibilities to your team appropriately, and have an actionable security plan in place to protect your Cloud assets.

    Speaker(s)
    Patrick Shumate, Solutions Architect, Splunk
    Stephen Alexander, Sr. Solutions Architect , Amazon Web Services

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1518.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Beginner

    0 min
  • Improve Your Cyber Monitoring & Response Strategy with Splunk Enterprise Security and Splunk Phantom [Splunk Enterprise Security, Phantom]
    How do you know if your alerting and response processes adequately cover the tactics and techniques that your adversaries will use against you? If you're not sure, then how do to you continuously improve to adapt to ever-evolving threats? This session will provide practical guidance on leveraging models like the diamond model, MITRE ATT&CK™, and OODA to deconstruct your monitoring and response program so that you can make strategic improvements and mature it on a strong foundation. Using these frameworks will help your team recognize its own bias in developing use cases, understand how its alerting and response coverage maps to adversary tactics/techniques, and develop and prioritize new use cases. The session will wrap up discussing practical tips for creating a continuous improvement program that helps you leverage Splunk Enterprise Security and Splunk Phantom to maintain a strong security posture.

    Speaker(s)
    Ed Svaleson, Accenture

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1545.pdf?podcast=1577146215

    Product: Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Integrating the Analyst, the Logic, and the Machine [Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML]
    Are your analysts spending too much time clearing through notable events? Ours were too, but today our analysts are living the dream: they have all the details they want right there on the Incident Review screen, all while our alerts fine-tune themselves (with workflow action human input). Come and see how we achieved Incident Review Screen 2.0. by using Splunk's Machine Learning Toolkit to transition to smarter correlation searches.

    Speaker(s)
    Lukasz Antoniak, Cyber Detection Crafting Chief, Viasat
    Ryan Rake, Viasat

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1673.pdf?podcast=1577146215

    Product: Splunk Enterprise Security, Splunk Machine Learning Toolkit, AI/ML

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Introducing Splunk Mission Control []
    Are you a security analyst? Do you like bright and shiny new things? Attend this session to get the inside scoop on the latest and greatest coming out of our security product and engineering teams.

    Speaker(s)
    Rob Truesdell, Sr Director, Product Management, Splunk
    Chris Simmons, Director of Product Marketing, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2371.pdf?podcast=1577146215

    Product:

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Introducing Splunk Mission Control []
    Are you a security analyst? Do you like bright and shiny new things? Attend this session to get the inside scoop on the latest and greatest coming out of our security product and engineering teams.

    Speaker(s)
    Rob Truesdell, Sr Director, Product Management, Splunk
    Chris Simmons, Director of Product Marketing, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2295.pdf?podcast=1577146215

    Product:

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • IOC's: Indicators Of Crap [Splunk Enterprise, Splunk Enterprise Security]
    “You should be looking at Indicators of Compromise!” exclaims your CISO, regulator, vendor, and mom. No problem, right? You have the most expensive security intelligence vendor and all you have to do is correlate in your expensive SIEM. If you've tried this, then you are laughing with me. Come hear my exploration into implementing IOCs at a major US insurance company and a major US bank. I’ll address the differences between Indicators of Compromise vs Indicators of Attack, and I will show you how not to use the MITRE ATT&CK™ framework, plus some tips on how it use it well. My goal is to save you from falling into the same pitfalls when dealing with Indicators of Crap.

    Speaker(s)
    Xavier Ashe, VP, Security Engineering, SunTrust Banks

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1111.pdf?podcast=1577146215

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides