Overview
Syllabus
Intro
Which Technologies?
Detection === Code That Finds Bad Stuff
Development Overhead Average time to write, test, and deploy a
Mo' Detections, Mo' Problems
No Support for Common Patterns
Components
Detection and Alert Abstraction
Config Inheritance
Modular Pre/Post Processing
Manual Tuning Lifecycle
Self-Tuning Alerts
Repetitive Investigations... What Happens?
Automated Investigation Templates
Automated Containment
Detection Testing
Detection Functional Tests
Databricks Stacks!
Deploy/Reconfigure Jobs with Single PR
Problem #1 - Cyclical Investigations
Problem #3 - Finding Patterns
Solution: Document Recommendations
Automated Suggestions
Anatomy of an Alert
Entity Tokenization and Enrichment
Suggestion Algorithm WHY CANTI
Taught by
Databricks