Just announced in preview: Mandiant Hunt for Chronicle Security Operations! This new service is tailored to organizations with existing security programs who want a threat hunting capability to discover new threats that may be missed by product detection.
https://t.co/jwXQWZi6JC
I’m proud to present ProtoBurp, a new Burp Suite extension to help encode and fuzz Protobuf messages based on pain points with existing tooling.
Check out my latest blog post about it! https://t.co/JH2O0OH9NF
#pentesting#burpsuite#protobuf#offsec
@CWambiru@Cyb3rMonk Anything we send to the SOC should be a lead that needs to be investigated, not a lead that needs triaged to determine if it should be investigated.
@Cyb3rMonk The SOCs job should purely be Investigation and Response. Send prioritized cases that consist of one to N number of detections correlated by a Classification rule, prioritization mapped to SOC SLOs.
@Cyb3rMonk That being said, I want to shift away from Classification being a SOC responsibility. I think it's our job as DEs to build a detection strategy that relieves the stresses of Classification on the SOC.
@securescientist @Cyb3rMonk Cool research @securescientist! I like the outlined process. You address this in the future research section, but I think one of the challenges SOCs have is time pressure incurred by SLOs. It'd be interesting to see how analyst perf changes as alert volume reaches max capacity.
@BakedSec Yeah 💯 agreed. I don't see hunting leads as being fundamentally different than alerts a SOC analyst would look at. Likelihood of malicious outcomes is less, but otherwise same same.
I don't feel like this is the right question. Threat hunting is a function of detection engineering, where detections are being tested and matched against customer telemetry. If not matches, no additional work. The question we should be asking is what is the service hunting for?
If you were procuring managed threat hunting services from a major security vendor, how many hours per week do you expect a threat hunter is threat hunting in your environment?
@MaxRogers5 I don't think the question is how much time is a hunter hunting, or even what sorts of malicious outcomes occur. It's about providing the customer with as much confidence we're searching for the right things, and we're evaluating leads that fall out of those searches.
@MaxRogers5 A customer should know a) what are we looking for b) what do we review. And not just goon summaries, show the data.
We shouldn't be afraid of customers checking our work. This will enable customers to make observe what gaps exist, so they can make smarter decisions.
I couldn't be prouder of my team for the work they did to implement auto containment at scale in Managed Defense. Auto containment stops impactful threats in their tracks.
Jon's tweet alludes to the challenge that this entails.
Here's a🧵on how we did it, and it's impact⬇️
How many folks perform auto remediation actions on alert creation?
E.g, an EDR alert is created with “Critical” severity; when any “Critical” sev EDR alert is created, auto contain the host(s). If alert is marked as “fp/benign” auto remove containment. If else, keep contained.
@LucyIsOpal @tommysec@PootSoHard Collect the number of alerts generated, their respective dispositions (fp/tp), and severity of reports they are associated with. Eventually this leads to what we call auto containment opportunities. We can target rules that are high efficacy and high impact for auto contain after