Explore the deployment of a serverless osquery backend for large-scale intrusion detection in this conference talk from BSidesSF 2020. Dive into the challenges of scaling osquery, an open-source community-driven endpoint detection tool, and learn about endpoint management and data transport considerations. Discover how to utilize Saltstack for osquery deployment, implement efficient data transport and storage solutions, and leverage big data exploration techniques. Gain insights into performance optimization, data visualization, and export methods for comprehensive security analysis.
Serverless Osquery Backend and Big Data Exploration