Early Detection Of Malicious Patterns In Event-Streaming Data | Hyrum Anderson | nullcon Goa 2019

50:23 · 01 Mar 2019 – 02 Mar 2019 · YouTube

About this talk

This talk explores the limitations of traditional static indicators of compromise in detecting adversarial activity, highlighting the need for behavioral indicators as organized in the MITRE ATT&CK framework. The speaker discusses the technical challenges posed by complex behaviors that span multiple events in an event stream, making detection cumbersome. Hyrum Anderson presents innovative tools for hunting known complex behavioral patterns and introduces a deep learning approach aimed at automatically discovering these behaviors from event logs. Anderson, the Chief Scientist at Endgame, leverages his extensive expertise in machine learning and information security to advance the field of adversary detection.

From event

nullcon Goa 2019

01 Mar 2019 – 02 Mar 2019

All event videos
Back to Watch