Cobot Uprising: Smart Automation for Blue Teams with Mark Orlando - SANS Blue Team Summit 2020

Subscribers:
23,600
Published on ● Video Link: https://www.youtube.com/watch?v=jp-PuLnd9EQ



Duration: 30:00
648 views
12


Despite using more automation than ever before in detection and response operations, organizations continue to be challenged by relatively unsophisticated attacks. Reliable detection requires time-consuming analysis and a level of data aggregation and correlation that is at best an art, and at worst cost-prohibitive. Meanwhile, attackers remain agile and inventive, continually (and rapidly) changing their infrastructure and approach with minimal costs and maximum benefit.

While there are some tasks that computers do far better than humans – such as rote and repetitive tasks and complex calculations – we will always be masters of analysis given our ability for complex thought, decision-making, and visual learning. With the introduction of security automation and orchestration to the defensive tool set, blue teams can now automate some of their investigative playbooks and save precious time. Unfortunately, this capability often drives automation for its own sake and expands tool sets that are already monolithic, rather than actually empowering our humans. Simply doing analysis faster is only a small part of the solution, and not all "improvements" are created equal!

How can we reframe this challenge to alter the calculus of attack and defense? Automation for the sake of doing so is a common trap that can actually degrade our capabilities and waste defensive cycles. However, applying automation in a controlled, strategic manner can be a game-changer for defenders. With proper planning and an incremental, product-neutral approach to automation, we can measurably improve our defenses and start leveling the playing field.

Mark Orlando @markaorlando, Co-Founder & CEO @bionic_sec; Instructor, @SANSInstitute




Other Videos By SANS Cyber Defense


2020-07-17Danger Stewards – Measuring Risk and Predicting the Future for Fun and Profit
2020-07-17Network Compromise for the Technically Challenged (Dummies)
2020-07-17You Can Write an Infosec Book!
2020-07-17ICMP: A world beyond ping
2020-07-17CISSP Test-Taking Tactics: Successfully Navigating Adaptive Exams
2020-07-08Threat Intelligence: How to Focus Fire on the Bad Guys Coming for Your Network-SANS Blue Team Summit
2020-07-08DevBlue: Applying Software Engineering Practices to Blue Teaming for the Win! -SANS Blue Team Summit
2020-07-08Put Some Power in Your Shell: POSH for Incident Response at Scale - SANS Blue Team Summit
2020-07-08Creativity, Convergence, & Choices: Security Analyst Thinking Modes - SANS Blue Team Summit
2020-07-08Threat Hunting via DNS with Eric Conrad - SANS Blue Team Summit 2020
2020-07-08Cobot Uprising: Smart Automation for Blue Teams with Mark Orlando - SANS Blue Team Summit 2020
2020-07-08Real-Time OSINT: Investigating Events as They Happen with Josh Huff | SANS OSINT Summit 2020
2020-07-08Weaponizing the Deep Web with Matt Edmondson - SANS OSINT Summit 2020
2020-06-28CISSP Cram Session | SANS Webcast Series
2020-06-18Putting Your SOC to the Test | John Hubbard
2020-06-13OSINT Reverse Image Searching with Search-By-Image - SANS OSINT Series
2020-06-13OSINT Video Verification with InVid, Google Maps & Street View - SANS OSINT Series
2020-06-13Why Video and Image Verification matters for OSINT? - SANS OSINT Series
2020-06-10DNS Fundamentals - SANS OSINT Series
2020-06-10Exploring DNS Data On The Web - SANS OSINT Series
2020-06-10Exploring DNS Data Using the Command Line - SANS OSINT Series