Ancestors

Written by Merospit on 2024-09-26 at 00:14

Next at #bsidescbr2024 is Brody Nisbet from Crowdstrike on how to strategically perform threat hunting to gain an advantage against adversaries.

=> More informations about this toot | More toots from merospit@infosec.exchange

Toot

Written by Merospit on 2024-09-26 at 00:17

"It's probably not cyberwar and it's definitely not chess" - Brody Nisbet

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Descendants

Written by Merospit on 2024-09-26 at 00:19

Raising the costs of adversaries works because resourcing, and hence money, is always a factor.

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Written by Merospit on 2024-09-26 at 00:26

A strategic Threat Hunting team needs to be separate from a day-to-day SOC, and should have clear priorities for each threat hunting project.

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Written by Merospit on 2024-09-26 at 00:30

Discoveries by strategic threat hunters must promptly be transferred to incident responders with actionable details.

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Written by Merospit on 2024-09-26 at 00:34

Discovery and followup can be slow but remediation should be quick.

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Written by Merospit on 2024-09-26 at 00:40

An internal threat hunting team can underatand the high value priorities for each network, which can't easily be outsourced to vendors.

[#]bsidescbr2024

=> More informations about this toot | More toots from merospit@infosec.exchange

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113200976588028637
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
390.953896 milliseconds
Gemini-to-HTML Time
1.072572 milliseconds

This content has been proxied by September (3851b).