Cloud Security Today

The world of purple teaming


Listen Later

Send us a text

This month, we welcome Eric Gagnon, Team Lead of Adversary Simulation, Purple Teaming, and Tradecraft Development at Desjardins. The conversation covers a wide range of topics related to cybersecurity, including purple teaming, red teaming, blue teaming, and Eric's journey in cybersecurity. Eric shares insights on certifications, threat hunting, cloud security, and the importance of knowledge exchange between red and blue teams. He also discusses the use of AI in cybersecurity and the need to stay sharp in the field.

Takeaways

  • Purple teaming involves collaborative operations to exchange ideas, evaluate security controls, and test out tactics, techniques, and procedures (TTPs) real threat actors use.
  • Certifications in cybersecurity, such as Offensive Security Certified Professional (OSCP) and Offensive Security Certified Expert (OSCE), provide valuable knowledge and an edge in the field.
  • Threat hunting involves looking for a granular activity that may indicate a compromise, filtering out the noise, and focusing on the suspicious behavior of threat actors.
  • Cloud security requires automation, cyber hygiene, and visibility, focusing on prioritizing techniques and testing them against the enterprise's environment.
  • Knowledge exchange between red and blue teams during a purple team engagement is essential and should include a common language, centralized documentation, and reporting against the MITRE ATT&CK framework.
  • Staying sharp in cybersecurity involves continuous learning, participation in CTFs, engaging with passionate individuals, and challenging oneself through talks, podcasts, and specialized training.

Chapters

00:00
Introduction to Purple Teaming and Cybersecurity Journey

08:09
Certifications and Insights in Cybersecurity

15:08
Threat Hunting and Granular Activity Detection

35:02
Knowledge Exchange in Purple Teaming: Red and Blue Collaboration

39:57
Staying Sharp in Cybersecurity: Continuous Learning and Engagement

The future of cloud security.
Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.

Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.

...more
View all episodesView all episodes
Download on the App Store

Cloud Security TodayBy Matthew Chiodi

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

14 ratings


More shows like Cloud Security Today

View all
Risky Business by Patrick Gray

Risky Business

360 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,467 Listeners

Pivot by New York Magazine

Pivot

8,916 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

202 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,849 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

77 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Think Fast Talk Smart: Communication Techniques by Matt Abrahams, Think Fast Talk Smart

Think Fast Talk Smart: Communication Techniques

777 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

117 Listeners

Coaching Real Leaders by Harvard Business Review / Muriel Wilkins

Coaching Real Leaders

642 Listeners

Cloud Security Podcast by Google by Anton Chuvakin

Cloud Security Podcast by Google

40 Listeners