SS-SUBJ-125: Detection Posture Management

Episode 125 September 12, 2023 00:32:26
SS-SUBJ-125: Detection Posture Management
Security Serengeti
SS-SUBJ-125: Detection Posture Management

Sep 12 2023 | 00:32:26

/

Show Notes

Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it.  These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier.  We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.

Vendor 1 - Cardinal Ops

Vendor 2 - SOC Prime

Vendor 3 - Anvilogic

Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 153

November 18, 2024 00:45:41
Episode Cover

SS-NEWS-153 - Lawyers will Inherit Cyber

This week we discuss an academic paper through Venture in Security talking about how companies will rely more and more on legal reasoning and...

Listen

Episode 39

December 12, 2021 00:38:46
Episode Cover

SS-SUBJ-39: Risk Based Alerting

In this episode, we discuss Risk Based Alerting, a new paradigm in alerting released in a talk at Splunk .conf in 2018.  We're big...

Listen

Episode 134

February 26, 2024 00:50:58
Episode Cover

SS-RPRT-137: The Blue Report

This week we take a look at the Picus Security Blue Report, and provide some analysis of the statements.  Interesting findings here.  The report...

Listen