Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

By SplunkTechnology
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides episodes

  • Build a JARVIS for Your SOC [Splunk Enterprise]
    The boss saw Ironman and wanted to create a JARVIS-like assistant for our SOC...so we built him one using Splunk. In this session we will share how we developed a Splunk virtual assistant to improve SOC efficiency and support the SOC 2.0 model of continual improvement. SOC JARVIS solves problems such as: How does a SOC manage its attack detection ideas and knowledge? How does an analyst understand the impact of their search changes on alert volumes? How does the SOC manage feedback between analysts and search authors? Learn how to use Splunk in a novel way to address these problems so that you can make your SOC workflows more efficient and let analysts spend more time threat hunting and improving how they detect attacks.

    Speaker(s)
    Jono Pagett, Head of Cyber Defence Centre, Bank of England
    Peter Littler, Cyber Security Analyst, Bank of England

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1597.pdf?podcast=1577146214

    Product: Splunk Enterprise

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Build Automated Decisions for Incident Response with Splunk Phantom [Splunk Enterprise, Phantom]
    Incident response (IR) analysts are required to make multiple decisions on every alert and incident. Whether the decision is to escalate, respond, or to discard the alert, each one of those decisions is critical to protecting their environment. With the integration of SOAR platforms like Splunk Phantom into IR teams, many of those decisions can now be automated for analysts. These decisions can save hours of work for analysts and allow for focus on more critical alerts. However, there are still questions to answer before implementing these decisions. What data is needed to make confident decisions? Where in the process should these decisions be made? How can existing decisions be improved? How should new decisions be integrated? The General Electric IR team has worked to answer these questions by using Splunk Enterprise and Splunk Phantom. In this session, we will show how our team approached these questions, implemented solutions, and integrated decisions for our analysts to save time and focus their efforts.

    Speaker(s)
    Mark Cooke, Staff Incident Responder, GE

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1446.pdf?podcast=1577146214

    Product: Splunk Enterprise, Phantom

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min
  • Building a Security Monitoring Strategy 2.0 [Splunk Enterprise Security, Splunk Machine Learning Toolkit, Phantom]
    So you have a SIEM with security data, e.g. firewalls, proxy, endpoint data, etc. Now what? How do you effectively operationalize your investment? This session provides recipes, principles, patterns, and strategies for using Splunk and data-driven analytics to move your security monitoring and compliance effectiveness up the maturity curve. This session will cover how to identify key mixes of data sources, core OOTB content to use, and how to layer capabilities aligned with your maturity. We will help you go beyond the endless alerts and investigations and start creating value by reducing the impact of potential security events. We're excited to show you that there's no need for a PhD in security assurance and operations—just Splunk and a solid plan.

    Speaker(s)
    Paul Davilar, Security Consultant, Splunk
    Paul Pelletier, Sr. Security Consultant, Splunk

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1391.pdf?podcast=1577146214

    Product: Splunk Enterprise Security, Splunk Machine Learning Toolkit, Phantom

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Building Behavioral Detections: Cross-Correlating Suspicious Activity with the MITRE ATT&CK™ Framework [Splunk Enterprise, Splunk Enterprise Security]
    Advanced attackers that live off your land add insult to what can be very serious injury. In this session we'll show you how to use behavioral analysis to identify advanced attackers that evade traditional signature-based detection methods. We do so in our organization by using Splunk to combine insights from traditional data sources to detect activity across multiple phases of the MITRE ATT&CK™ framework. We'll focus on how to build queries  tune them for your environment, and start catching these threat actors with behavioral detections as soon as you get back from .conf.

    Speaker(s)
    Haylee Mills, Security Engineer, Charles Schwab

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1556.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Intermediate

    0 min
  • Building threat-driven use cases for the real world with iDefense intelligence [Splunk Enterprise, Splunk Enterprise Security]
    Where did you come up with the idea for your last use case? Traditional approaches to use case ideation focus on identifying new use cases based on the data already available to the security operations center. However, the threat landscape is constantly changing, and attackers are constantly getting more sophisticated. To detect these advanced threats, our use cases must be based on both business and threat context. In this session, we will share our approach to building innovative use cases based on real-world threats. Starting with industry-specific threat intelligence, we identify the threat actors and their specific tactics, techniques, and procedures. With these insights, we identify use cases relevant to the business, map them to both existing and new data sources, and prioritize implementation based on the specific threats.

    Speaker(s)
    John Rubey, Accenture

    Slides PDF link - https://conf.splunk.com/files/2019/slides/SECS2797.pdf?podcast=1577146214

    Product: Splunk Enterprise, Splunk Enterprise Security

    Track: Security, Compliance and Fraud

    Level: Good for all skill levels

    0 min

About Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

From the publisher's feed

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides