AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
How to Detect an Insider Threat With Automated Alerts
i think one of the most effective things that we've done and this is all public stuff um is we have a really elaborate teard system of triaging alerts through uh through slack and chat apps and stuff like that so it's everything from informational words hey you know someone just enrolled in a device and mem right the microsoft endpoint manager. i don't want every single IR alert for someone hooking up a phone to go to an analyst but send an automated alert to the recipient and give them the ability to escalate it if they don't recognize it. get a sense of yeah this is really spooky or or no this is probably benign and some of the strategies that you invoke there