Creating Effective Sigma Rules with AI

  Рет қаралды 597

Cloud Security Podcast

Cloud Security Podcast

Күн бұрын

Can Threat Detection be enhanced with AI? Ashish sat down with Dave Johnson, Senior Threat Intelligence Advisor at Feedly, at BSides SF 2024, where Dave also presented a talk.
Dave shares his journey in cyber threat intelligence, including his 15-year career with the FBI and his transition to the private sector. The conversation focuses on the innovative use of large language models (LLMs) to create Sigma rules for threat detection and the challenges faced along the way. Dave spoke about his four approaches to creating Sigma rules with AI, ultimately highlighting the benefits of prompt chaining and Retrieval Augmented Generation (RAG) systems.
Questions asked:
00:00 Introduction
01:44 A word for our episode sponsor, Panoptica
02:39 A bit about Dave Johnson
03:33 What are Sigma Rules?
04:36 Where to get started with Sigma Rules?
05:27 Skills required to work with Sigma Rules
06:32 The four approaches Dave took to Sigma Rules
11:29 Are Sigma Rules complimentary to existing log systems?
12:18 Challenges Dave had during his research
14:09 Validating Sigma Rules
16:01 Working on Sigma Rule Projects
18:54 The Fun Section
Resources
Dave's Webpage: daveinthemiddle.com/
Sigma HQ GitHub:github.com/SigmaHQ/sigma
--------------------------------------------------------------------------------
📱Cloud Security Podcast Social Media📱
_____________________________________
🛜 Website: cloudsecuritypodcast.tv/
🧑🏾‍💻 Cloud Security Bootcamp - www.cloudsecuritybootcamp.com/
✉️ Cloud Security Newsletter - www.cloudsecuritynewsletter.com/
Twitter: / cloudsecpod
LinkedIn: / cloud-security-podcast
#cloudsecurity

Пікірлер
Why Identity and Edge Security Matters for Cloud Security?
21:10
Cloud Security Podcast
Рет қаралды 787
What is AI-SPM?
23:29
Cloud Security Podcast
Рет қаралды 676
Best father #shorts by Secret Vlog
00:18
Secret Vlog
Рет қаралды 21 МЛН
Каха и суп
00:39
К-Media
Рет қаралды 5 МЛН
AI's Impact on Real-World Problems | Kelsey Hightower
34:25
Cloud Security Podcast
Рет қаралды 384
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 649 М.
Is AGI Just a Fantasy?
41:26
Machine Learning Street Talk
Рет қаралды 44 М.
Real-World Cloud Security Challenges and Solutions Explained for 2024
59:24
Cloud Security Podcast
Рет қаралды 1,6 М.
Scaling DevSecOps for Cloud in 2024
21:03
Cloud Security Podcast
Рет қаралды 1,2 М.
Proactive Security Strategies for AI Integration
33:56
Cloud Security Podcast
Рет қаралды 690
What is the future of security operations with AI in 2024?
23:10
Cloud Security Podcast
Рет қаралды 999
Why You Should Learn AI In Cybersecurity
36:34
PurpleSec
Рет қаралды 3,3 М.
Best father #shorts by Secret Vlog
00:18
Secret Vlog
Рет қаралды 21 МЛН