SS-SUBJ-125: Detection Posture Management

Episode 125 September 12, 2023 00:32:26
SS-SUBJ-125: Detection Posture Management
Security Serengeti
SS-SUBJ-125: Detection Posture Management

Sep 12 2023 | 00:32:26

/

Show Notes

Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it.  These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier.  We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.

Vendor 1 - Cardinal Ops

Vendor 2 - SOC Prime

Vendor 3 - Anvilogic

Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 34

November 07, 2021 00:33:31
Episode Cover

SS-SUBJ-34: Purple Teaming

In this episode we discuss the Purple Team.  What is it, and why is it David's favorite color?   Supporting Articles:The Difference Between Red, Blue,...

Listen

Episode 134

February 26, 2024 00:50:58
Episode Cover

SS-RPRT-137: The Blue Report

This week we take a look at the Picus Security Blue Report, and provide some analysis of the statements.  Interesting findings here.  The report...

Listen

Episode 37

November 30, 2021 00:55:04
Episode Cover

SS-NEWS-37: Default Passwords to be banned?

In this episode, we reviewed some recent news articles that caught our eye, including how to choose your MSP, will the UK ban default...

Listen