SS-SUBJ-39: Risk Based Alerting

Episode 39 December 12, 2021 00:38:46
SS-SUBJ-39: Risk Based Alerting
Security Serengeti
SS-SUBJ-39: Risk Based Alerting

Dec 12 2021 | 00:38:46

/

Show Notes

In this episode, we discuss Risk Based Alerting, a new paradigm in alerting released in a talk at Splunk .conf in 2018.  We're big fans, and we discuss it from start to finish, and share some stats on how much it improved alerting at the companies who have implemented it.

You have to register at Splunk's .conf site to watch the talks, but it's free.  The talks themselves can be found here: https://conf.splunk.com/watch/conf-online.html

After registration and logging in, search for "Risk Based Alerting" and that will get you the majority of the talks.  

If you found this interesting or useful, please like and subscribe, and follow us @serengetisec for more!  Without that social validation, we just sulk around the house all day.

Other Episodes

Episode 7

April 25, 2021 00:47:58
Episode Cover

SS-NEWS-007: TLS Encryption and Solarwinds Discovered Early?

In this episode, we deep dive into two articles, linked below:Half of Q1's malware traffic observed by Sophos was TLS encrypted, hiding inside legit...

Listen

Episode 152

November 04, 2024 00:40:51
Episode Cover

SS-DISC-152 - Detection Engineering Behavior Maturity Model

Today we discuss the Detection Engineering Behavior Maturity Model, which is a new Capability Maturity Model for Detection Engineering (surprise!) from Elastic.  It seems...

Listen

Episode 147

July 29, 2024 00:49:14
Episode Cover

SS-NEWS-147 - Does Phishing Education need to mature like Fire Drills did?

This week David and I talk about how current phishing tests closely resemble early attempts at fire drills, through the Google Security Blog, and...

Listen