YoVDO

Reducing Inactionable Alerts via Policy Layer

Offered By: BSidesLV via YouTube

Tags

Security BSides Courses Cybersecurity Courses

Course Description

Overview

Explore strategies for minimizing false positives and inactionable alerts in security systems through a conference talk from BSidesLV 2019. Delve into key concepts including whitelists, policy layers, and generalized ability as presented by John Seymour. Learn how to implement a separate policy layer to enhance alert management and improve overall security effectiveness. Examine the potential trade-offs of this approach and discuss potential improvements. Gain insights into integrating these techniques into existing security infrastructures and understand their impact on alert reduction. Conclude with a Q&A session to address specific implementation concerns and further clarify the presented concepts.

Syllabus

Introduction
Definitions
Examples
Whitelists
Separate Policy Layer
Generalized Ability
Integration
What we lose
Improvements
Questions


Taught by

BSidesLV

Related Courses

Early Detection through Deception
YouTube
Hack for Show, Report for Dough - Brian King
YouTube
Blue Teamin on a Budget of Zero - Kyle Bubp
YouTube
Windows Event Logs - Zero to Hero
YouTube
Weaponizing Splunk - Using Blue Team Tools for Evil
YouTube