Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Attacking and Defending Kubernetes: A Purple Team Approach to Improving Detection Using Splunk Enterprise Security, Splunk Phantom and Peirates [Splunk Enterprise Security, Phantom]
    Would you be able to detect a sophisticated adversary targeting your Kubernetes clusters and workloads tonight? How do busy teams with stacked backlogs find time to learn how to attack Kubernetes clusters, detect those attacks, and build defenses to reduce the attack surface? We will demonstrate an effective purple team methodology that "uses every part of the buffalo" by 1) executing attacks on Kubernetes using the open source tool Peirates, 2) tracking the attack artifacts from the adversary simulation in Splunk, 3) teaching the defenders how the attack was performed and where to look for forensic artifacts, and 4) working together in the purple-est way possible to improve detection and response capabilities using Splunk Enterprise Security, Splunk Phantom, and Peirates.

    Speaker(s)
    Brian Genz, Senior Manager, Threat & Vulnerability Mgmt., Splunk
    Jay Beale, CTO, InGuardians

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2286.pdf?podcast=1577146214

    Product: Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • ATT&CK™ing Linux with SPL [Splunk Enterprise, Splunk Enterprise Security]
    In this session we will discuss using Splunk to detect a range of Linux-based adversary techniques from MITRE’s ATT&CK™ framework. We will also demonstrate how event sequencing can be used to map a path through the ATT&CK™ matrix and improve overall detection fidelity. We will provide auditd configuration suggestions for Linux endpoints to support greater coverage.

    Speaker(s)
    Doug Brown, Senior Information Security Analyst, Red Hat

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1156.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • ATT&CK™ Yourself Before Someone Else Does [Splunk Enterprise, Splunk Enterprise Security, Phantom]
    Do you love the idea of the MITRE ATT&CK™ framework, but you’re not sure how to use it in your Splunk-centric security program? This talk will teach you practical ways to use the framework in your own organization and the Splunk security tools that will help you do so. We'll start the talk by identifying an adversary and some of their known techniques, and then we'll show how to choose an appropriate set of detections and how to test whether those detections are working as expected. You'll leave the talk better able to take advantage of threat intelligence, cover the right set of ATT&CK™ tactics and adversary groups, and eliminate organizational blind spots.

    Speaker(s)
    BOTSFATHER Kovar, Principal Security Strategist, Splunk
    John Stoner, Principal Security Strategist, Splunk
    Dave Herrald, Principal Security Strategist, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1927.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Beginner

    0 min
  • Augment Your Security Monitoring Use Cases with Splunk's Machine Learning Toolkit [Splunk Enterprise, Splunk Machine Learning Toolkit, AI/ML]
    Do you want to use machine learning to enhance your datacenter security monitoring, but you don’t know where to start? Then this is the talk for you. Come learn how high secure datacenter operations benefit from operationalizing machine learning. With the help of the Splunk's Machine Learning Toolkit, your security analysts can take different approaches to use case creation and gain new insight into what's going on in your environment. We'll detail the challenges, benefits and use cases of using machine learning for datacenter security monitoring, and we'll answer questions such as: Where does it make sense to apply machine learning, and where should we stick with classic searches? Can we detect meaningful anomalies in system behavior? Is it possible to cluster our account activities and find unusual patterns? This is a practical session of security monitoring use cases, deep diving into the ideas, concepts and the SPL behind them.

    Speaker(s)
    Oliver Kollenberg, Security Consultant, Siemens
    Philipp Drieger, Staff Machine Learning Architect , Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1374.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Machine Learning Toolkit, AI/ML

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Automate Forensic Investigations in AWS with Splunk [Splunk Enterprise]
    Alerts in cloud environments require your team to quickly and precisely gather evidence and isolate affected environments. The GE Digital Predix Incident Response (IR) team found an abundance of content for analyzing forensic evidence from Windows environments, but they noticed a gap in content built for performing investigations on Linux-based hosts. The Predix IR team will discuss the tools they have built to contain a compromised Linux-based hosts, gather evidence, and analyze that evidence in Splunk. Utilizing splunk searches, lookups, and visualization components to look both narrowly into the data set as well as broadly across the rest of the environmental data in splunk to identify known bad or potentially suspicious activities that may warrant further investigation by an analyst. 

    Speaker(s)
    David Rutstein, Principal Analyst, GE
    Alina Dejeu, Incident Responder, GE

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1479.pdf?podcast=1577146214

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Automate Your Phishing Response with Splunk Enterprise Security, Splunk Phantom, and Machine Learning [Splunk Enterprise, Splunk Enterprise Security, Phantom]
    We developed an automation framework that classifies and mitigates emails reported to the SOC. The framework acts as an engine that consumes multiple data sources, including a supervised machine learning model and a risk scoring algorithm to assess with high confidence if an email is phishing, spam, or benign. We will discuss the benefits of our approach to phishing mitigation, such as enhancing our SOC's ability to automatically identify, prioritize, and mitigate malicious phishing attempts against employees before any damage is done. The session will outline the overall design of the framework, detail the primary components that are used within Splunk Phantom and Splunk Enterprise Security, and will outline the supervised machine learning model that we trained to aide the automation engine.

    Speaker(s)
    Mackenzie Kyle, Manager - Cybersecurity Operations Center, JPMorgan Chase
    Benji Arnold, Sr. Security Analyst , JPMorgan Chase
    Dennis Rhodes, Sr. Security Analyst, JPMorgan Chase

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1128.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security, Phantom

    Track: Security, Compliance and Fraud

    Level: Advanced

    0 min
  • Best Practices for Rapid Containment of Incidents [Splunk Enterprise, Phantom]
    Prevention and detection solutions are vital to maintain a healthy network but not sufficient.When a security incident occurs, the ability to investigate rapidly and recover is crucial but is manually intensive, especially when dealing with networks spanning on premise, public, and private cloud environments.Once an incident is detected, then what?Learn how RedSeal integrates within Splunk Enterprise Security and Phantom framework to provide you with immediate answers to burning questions.

    Speaker(s)
    Noam Syrkin, Sr. Technical Marketing Engineer, RedSeal

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SECS2841.pdf?podcast=1577146214

    Product: Splunk Enterprise, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Beyond Tier 1 Automation: The Hidden Value of Splunk Phantom Automation for Security Operations [Splunk Enterprise, Phantom]
    You've probably heard examples of Splunk Phantom automating 90% of Tier 1 processes, but did you know that Phantom improves human-lead processes too? Come learn about the hidden value of validation and utility playbooks from Penn State University’s Enterprise Security Manager and Splunk’s Lead Technologist for Higher Education. Validation playbooks are automated tests run to validate a human judgement or request. Utility playbooks are short easy-to-create playbooks in Phantom that an analyst  runs during an investigation.  We’ll cover when to use validation and utility playbooks, how to get started creating them, and ideas for other playbooks you can use to improve your daily operations.

    Speaker(s)
    Craig Vincent, Lead Technologist,SLED, Splunk
    Chris Decker, Enterprise Security Manager, Penn State University

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2205.pdf?podcast=1577146214

    Product: Splunk Enterprise, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Break Down Silos By Ingesting Multi-Purpose Data Sources into Splunk [Splunk Enterprise]
    We use Splunk data to help previously siloed groups at Qualcomm work better together. We will discuss specific high value, multipurpose data sources that we ingest, and how we use them to foster collaboration across teams. You will leave this session with a better sense of data sources that you analyze for security that can also help you work better with everyone from developers, to help desk staff, to executive management.

    Speaker(s)
    Ben Marcus, Sr. Staff IT Engineer, Qualcomm

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC2280.pdf?podcast=1577146214

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Beginner

    0 min
  • Break Free From Legacy GRC to Achieve Real-Time Integrated Risk Visibility [Splunk Enterprise]
    As organizations shift away from legacy Governance, Risk, and Compliance (GRC) approaches towards an integrated risk management (IRM) strategy, cyber risk management paradigms must also shift. This presentation will address why firms are shifting to IRM and how the shift to IRM will affect security organizations globally. We will showcase strategies used by forward-leaning peers and thought leaders to operationalize integrated risk management programs in their organizations.

    Speaker(s)
    Matt Coose, Qmulos
    Anthony Perez, Director of Field Technology - Public Sector, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1930.pdf?podcast=1577146214

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides