Early Detection Of Malicious Patterns In Event-Streaming Data | Hyrum Anderson | nullcon Goa 2019
About this talk
This talk explores the limitations of traditional static indicators of compromise in detecting adversarial activity, highlighting the need for behavioral indicators as organized in the MITRE ATT&CK framework. The speaker discusses the technical challenges posed by complex behaviors that span multiple events in an event stream, making detection cumbersome. Hyrum Anderson presents innovative tools for hunting known complex behavioral patterns and introduces a deep learning approach aimed at automatically discovering these behaviors from event logs. Anderson, the Chief Scientist at Endgame, leverages his extensive expertise in machine learning and information security to advance the field of adversary detection.
More from this event
See all 40 talks →
Interview with Robert Baptiste aka Elliot Alderson [@fs0c131y] by Antriksh Shah | nullcon Goa 2019
25:01
Getting to $10,000 – the variables at play in determining bounty awards by Jarek Stanley
20:08
A Hacker Walks Into A Co-Working Space | Rahul Binjve (@c0dist) | nullcon Goa 2019
33:10
Andromeda- GUI based Dynamic Instrumentation Toolkit powered by Frida | Shivang Desai | nullcon 2019
21:08