Behavior Analytics in Your Security Data Lake Just Got Way Easier
I’m no data scientist, but I know machine learning can be a SOC’s best friend. In a previous role, my security engineering team had to convince our management (and ourselves) that we would get alerted if the Capital One hacker tried the same attack with us. Machine learning for behavior analytics gave us a way to detect a compromised AWS account trying to steal documents from our cloud. And now, prebuilt machine learning functions in Snowflake cut the effort involved from weeks to hours. And you don’t need to be a data scientist to use them. The hacker “erratic” behind one of the largest breaches of all time was not stealthy. She bragged about copying over 30 GB of documents out of 700 cloud storage buckets. Despite all that activity, the breach stayed undetected from March to July. When we read the breach reports, my team knew we needed detection time that would not be measured in months. Could behavior analytics help detect this kind of cloud breach? We considered how a compromised a
Behavior Analytics in Your Security Data Lake Just Got Way Easier Snowflake's new machine learning functions bring ML to SOCs without data scientists Omer Singer Mar 07, 2024 4 Share I’m no data scientist, but I know machine learning can be a SOC’s best friend. In a previous role, my security engineering team had to convince our management (and ourselves) that we would get alerted if the Capital One hacker tried the same attack with us. Machine learning for behavior analytics gave us a way to detect a compromised AWS account trying to steal documents from our cloud. And now, prebuilt machine l
Explore this link on the map →related reading
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- How Dropbox Implemented a Modern SIEMsnowflake.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Creating Cost-Effective, Scalable Detectionsrippling.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Tactical Guide to Threat Hunting in Snowflake Environmentsmitiga.io
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Security data lakehouse and modular designrippling.com