Augmenting the Onion: Facilitating Enhanced Detection and Response with Open Source Tools

Presented at CackalackyCon 1 (2019), June 1, 2019, 10 a.m. (60 minutes)

As network defenders, we face evolving threats every day, and are required to truly understand our computer networks; to gain perspective around normal (and abnormal) behavior, and the scope of an event. To help us better understand and protect our systems, we can use completely free and open source tools, augmenting a platform like Security Onion, to assist us in threat hunting, responding to alerts, tracking events, automating analysis of files extracted from network data streams, and even performing remote host-based forensics. This talk delves into tools that are freely available, and how they can be integrated to empower even the smallest of information security departments to effectively monitor, track, and investigate events to help lower risk and increase security posture within their organizations. Audience members should walk away from the talk with a better understanding of the open source tools at their disposal, and how they can begin to immediately realize the benefits of said tool usage within their environments.


Presenters:

Links:

Similar Presentations: