SS-SUBJ-125: Detection Posture Management

Episode 125 September 12, 2023 00:32:26
SS-SUBJ-125: Detection Posture Management
Security Serengeti
SS-SUBJ-125: Detection Posture Management

Sep 12 2023 | 00:32:26

/

Show Notes

Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it.  These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier.  We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.

Vendor 1 - Cardinal Ops

Vendor 2 - SOC Prime

Vendor 3 - Anvilogic

Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 85

November 07, 2022 00:29:17
Episode Cover

SS-NEWS-085: Deepfake Hysteria, IIS Server Logs as C2!

Several short stories for your consideration on this fine November day. First, Sophos thinks we're on the hysteria part of the FUD Curve where...

Listen

Episode 64

June 06, 2022 00:35:20
Episode Cover

SS-NEWS-064: Social Engineering Kill Chain Model!

In this episode, we discuss a Kill Chain-like model for Social Engineering attacks.  We were going to do two articles, but we went deep. ...

Listen

Episode 96

January 30, 2023 00:44:28
Episode Cover

SS-NEWS-096: Davos Ransomware Discussion!

Snark abounds in this episode, where we discuss the rich folks at Davos getting a briefing on ransomware, ransomware takings down year over year,...

Listen