Главная
Study mode:
on
1
Intro
2
Welcome
3
Background
4
Problems
5
Bitbucket
6
Splunk
7
Summary
8
Standardized ER
9
Metadata
10
Feedback loop
11
Deeper souptonuts
12
Core data
13
Short name
14
linting failures
15
valid tactic
16
spawn query
17
transformations
18
Secondary operations
19
confluence
20
Search stanzas
21
PR links
22
CI process
23
Application
24
Demo
25
Custom issue type
26
Issue Key
27
Data Source
28
Issue Summary
29
Repos
30
Extended Response
31
Spunk
32
Conflict parser
Description:
Explore a standardization framework for security alerts in this conference talk from Circle City Con 2019. Learn about the Standardizer tool, which addresses common problems in alert management. Discover how to implement standardized emergency response metadata, create feedback loops, and handle core data effectively. Dive into topics such as short name linting failures, valid tactics, spawn queries, and transformations. Gain insights on secondary operations, Confluence integration, search stanzas, and the CI process. Watch a demonstration of custom issue types, issue keys, data sources, and extended responses. Understand how to leverage Bitbucket, Splunk, and other tools to improve your security alert workflow.

Standardizer - A Standardization Framework for Your Security Alerts

Add to list
0:00 / 0:00