SS-SUBJ-125: Detection Posture Management

Episode 125 September 12, 2023 00:32:26
SS-SUBJ-125: Detection Posture Management
Security Serengeti
SS-SUBJ-125: Detection Posture Management

Sep 12 2023 | 00:32:26

/

Show Notes

Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it.  These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier.  We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.

Vendor 1 - Cardinal Ops

Vendor 2 - SOC Prime

Vendor 3 - Anvilogic

Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 32

October 24, 2021 00:24:17
Episode Cover

SS-CONF-32: Splunk .conf 21, Part 1

In this episode, we talk .Conf!  David and I attended Splunk .conf remotely and sit down to discuss this years presentations and announcements.  Unfortunately,...

Listen

Episode 50

February 28, 2022 00:58:56
Episode Cover

SS-NEWS-050: Low Code Development and Hackers planting evidence!

In this episode we discuss securing Low- and No-Code development, hackers who plant evidence of crimes, US Justice Department announcing it will attack hackers...

Listen

Episode 121

August 07, 2023 00:32:21
Episode Cover

SS-NEWS-121: Phones as Snitches and the End of Log Centralization?

This week we discuss the TSA and their endless privacy invasions (this time... facial recognition!), an Anton Chuvakin post on the end of Log...

Listen