Blueprint: Build the Best in Cyber Defense cover image

Strategy 7: Select and Collect the Right Data

Blueprint: Build the Best in Cyber Defense

00:00

How to Find Dead or Broken Data Feeds

Doing it on a per server basis unless that server is subject to extreme regulatory or audit scrutiny is probably over aggressive. However, taking a moving average weighted approach to where if you see data go way high or way low against a moving average can be ruthlessly effective. What I would advise people against is building static lists. Don't build static lists. Have the system automatically build the list from what it's seen before and compare that against what it has seen recently. This kind of analysis can be done in a single query that can be run on a timer. And it might not catch something in 15 minutes, although you could. You could do it very quickly. I have found this effect

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app