Blueprint: Build the Best in Cyber Defense cover image

Strategy 7: Select and Collect the Right Data

Blueprint: Build the Best in Cyber Defense

00:00

The Importance of EDR in Interruption Detection and Incident Response

When I'm doing incident response, the in memory stuff has been the most valuable because you can kind of see as things are changing and what's happening that's weird. But that in memory data is super hard to hold onto. It's ephemeral. So it disappears the minute someone's logged off the system or turned off whatever to, you know, blew away their VM. For me, that's the ideal place is in memory. Having that wealth of data at your fingertips is tremendously empowering to the analysts so that they don't have to do this highly laborious disc or even memory forensics after the fact.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app