AI Security Researcher @nvidia | Prev: @Microsoft | Founder of the @OTR_Community
Oct 4, 2022 β’ 9 tweets β’ 7 min read
@jsecurity101 is next @SANSDefense ! Once upon a Login! Understanding logon sessions to add more context to your detection strategy ππ₯
The logon process structure and some of the logon context switch that we need to understand during investigations ππΉ A Logon Session centric data approach ! Save time! Accurate!
@tifkin_ Hermanooo π @Cyb3rPandaH and I were talking about some of those concepts while writing a workshop/training, and we decided to put a few things on the board ππ€£ There are a few things that need to be taken in consideration from a distribution & operationalization of detections @tifkin_@Cyb3rPandaH Regarding distribution we believe that besides just sharing a query, there needs to be other considerations to make sure that the detection being shared is of quality and that it could also encourage others to build on the top of it,