Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Detection Engineering without Alert Fatigue - Correlating Minor Detections

NorthSec via YouTube

Overview

Explore the challenges of balancing detection coverage and alert fatigue in a Security Operations Center (SOC) through this 25-minute conference talk from NorthSec. Discover how a custom platform leveraging the concept of indicators was developed to correlate minor or noisy detection logics. Learn about the toolset and implementation details used to monitor tens of thousands of endpoints effectively. Gain insights into how this platform has become a crucial tool for threat hunting and assists SOC analysts in their investigations. Understand the journey of building a detection engineering system that avoids common pitfalls, such as generating alerts for benign activities like executing the 'whoami' command.

Syllabus

NSEC2023 - Willy Wonka and the Detection Factory: Detection Engineering without Alert Fatigue

Taught by

NorthSec

Reviews

Start your review of Detection Engineering without Alert Fatigue - Correlating Minor Detections

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.