view_agenda Chapters
auto_awesome Transcript
info_circle Episode notes
Guest:
Topics:
-
What is good detection, defined at micro-level for a rule or a piece of detection content?
-
What is good detection, defined at macro-level for a program at a company?
-
How to reliably produce good detection content at scale?
-
What is a detection content lifecycle that reliably produces good detections at scale?
-
What is the purpose of a SIEM today?
-
Where do you stand on a classic debate on vendor-written vs customer-created detection content?
Resources: