Hook
More breakout videos from this creator.
How do you is worth Gut Feeling If it looks I escalate it. Context First I check the context Who triggered it, what system, what time, and whether there is activity around it, then I decide. Walk me through investigate an alert, No Process look at the logs, I escalate it if it looks bad. Repeatable Process the source, identify and the user, the evidence, and document everything before I decide. What is a SIEM, and how do you use it? Just a Tool It collects logs and shows alerts if something looks bad. Investigation Engine events across identity, network, and cloud. I use it to build a clear timeline before I decide escalate or close it. What is the between IDS and IPS? Textbook Answer The IDS detects and the IPS blocks. SOC Mindset IDS alerts you to suspicious activities whereas IPS can block that activity, but you still need to validate that block or not. What is a false positive and how do you reduce them? Quick Fix If it's a wrong alert I just tune it doesn't fire again. It's legitimate Root Cause Thinking activity suspicious. I trace why the rule fired, add the right context, adjust carefully, and I'm not creating a blind spot in the process. Ready to break into cybersecurity but don't know where to start? Follow my account Follow for more! exactly how to start!