SIEM Rules - Eric Capuano, Tim MalcomVetter - ESW #323

Published: July 14, 2023, 9 p.m.

b'

InfoSec might have a hoarding problem, but it\\u2019s easy to understand why. It\\u2019s almost impossible to know what logs you\\u2019re doing to need, when you\\u2019re going to need them, or for what reason. SIEM vendors have taken advantage of these InfoSec data FOMO tendencies, however, and are making a killing charging a premium for storage - even when the storage in question is your own on-prem hardware. There ARE alternatives, however, but it seems most folks aren\\u2019t aware of this. In this interview with Eric Capuano, we\\u2019ll discuss both the practical and economic shortcomings of the traditional SIEM model. We\\u2019ll discuss the challenges of various SIEM use cases. Most importantly, we\\u2019ll discuss the new models actively replacing them. (No, they\\u2019re not branded as next-gen SIEMs) Tim MalcolmVetter has been alternating between blue team and red team roles for years. Moving between the two has had its advantages, giving Tim a better understanding of what works, what doesn\\u2019t and why. We\\u2019ll discuss a variety of topics, including the pros and cons of industry talent pipelines, Kerberoasting, and AI trends.

2023 Cybersecurity Conversations Report:\\xa0https://eb1x.co/NWn0RHK Segment description coming soon!

Visit https://www.securityweekly.com/esw\\xa0for all the latest episodes!

Follow us on Twitter: https://www.twitter.com/securityweekly\\xa0

Like us on Facebook: https://www.facebook.com/secweekly

\\xa0Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw-323

'