Founder of Panther, Jack Naglieri, discusses detection-as-code approaches on a podcast covering Palo Alto's firewall vulnerabilities, Sisense data breach, FISA reauthorization, Apple's India link, and more cybersecurity news.
Implementing business and identity logic into detection rules enhances accuracy.
Advanced data analysis techniques like AI improve detection capabilities against modern attacks.
Combining high and low signal events from various sources strengthens threat identification.
Deep dives
Main Focus on Detection as Code
The use of detection as code in real-world scenarios is emphasized, focusing on covering tactics and techniques relevant to a specific company. Implementing business logic and identity logic into detection rules, based on reliable data correlations, is highlighted to enhance detection accuracy.
Enhanced Data Analysis
Incorporating historical context and advanced data analysis techniques like deterministic correlations and AI for improved detection capabilities. The discussion also addresses the challenge of modern attacks mimicking normal behavior to avoid detection.
Signaling Complexity and Contextual Triggers
Emphasizing the importance of combining high and low signal events for robust detection. Integrating different sources such as guard duty alerts and benign activities to create meaningful correlations for identifying potential threats.
Varied Adoption Patterns
Organizations of different sizes and backgrounds are transitioning towards cutting-edge detection techniques. While some are replacing legacy systems like Splunk with data lake approaches, others are incorporating detection as code in cloud-centric or high-scale environments.
Evolution of Security Operations
Transitioning from EPS limits in legacy SIMs to modern, cloud-native security operations that focus on auto-scaling, serverless architectures, and agile detection methodologies, reflecting a shift towards contemporary approaches in security operations.
On this week’s show Patrick and Adam discuss the week’s security news, including:
Palo Alto’s firewalls have a ../ bad day
Sisense’s bucket full of creds gets kicked over
United Healthcare draws the ire of congress
FISA 702 reauthorisation finally moves forward
Apple warns about “mercenary exploitation” but what’s the India link?
And much, much, more
This week’s sponsor is Panther, a platform that does detection as code on massive amounts of data. Panther’s founder Jack Naglieri is this week’s sponsor guest, and we spoke with him about some common detection-as-code approaches.