If your SOC is well-versed in the organization’s data sources, you can easily automate the assessment of potential threats and prioritize tasks for developing detectors. But what if the SOC discovers a legacy system without documentation? And if there are not one, but ten such non-standard systems? The presentation describes a methodology for connecting non-standard sources, as well as universal rules that can cover most important security events even in a non-standard system.
Event: PHDays
VIDEO RECORDING
Standard rules for non-standard sources
·1 min·

