YoVDO

Automating Incident Response

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Incident Response Courses Ontology Courses Operational Efficiency Courses

Course Description

Overview

Explore the benefits and implementation of automated incident response in this 48-minute Black Hat conference talk. Discover how automation can overcome inefficiencies and accelerate response times in cybersecurity operations. Learn about the current challenges in incident investigations, the concept of Mean Time to Know, and why traditional methods are time-consuming. Delve into a capability framework and investigation engine, understanding their building blocks and the importance of a comprehensive ontology. Gain insights into ontology visualization and practical examples. Conclude with key takeaways and future directions for automating incident response, as presented by Elvis Hovor and Mohamed El-Sharkawi.

Syllabus

Introduction
Current Challenges
Incident Investigations
Mean Time to Know
Why is it taking so much time
Benefits of automation
Capability Framework
Investigation Engine
Building Blocks
Comprehensive Ontology
Ontology Visualization
Ontology
Example
Learning
What Next
Takeaways


Taught by

Black Hat

Related Courses

Bioinformatics: Introduction and Methods 生物信息学: 导论与方法
Peking University via Coursera
Information Service Engineering
openHPI
Linked Data Engineering
openHPI
Основы философии: о чем спорят философы сегодня
Higher School of Economics via Coursera
Plato, Socrates, and the Birth of Western Philosophy | 西方哲学精神探源
Tsinghua University via edX