本页内容尚不支持所选语言。Elastic 正在不断努力,以实现对多种语言内容的支持。感谢您在此期间给予的耐心与陪伴!

点播网络研讨会

Elastic Security: Introducing the public repository for detection rules

主办方:

Paul Ewing

Paul Ewing

高级产品经理

Elastic

Ross Wolf

Ross Wolf

Senior Security Research Engineer

Elastic

概述

Security must be a team sport — collaborating, sharing, and contributing are critical to success. Working together on a larger scale is the only way to stay ahead; infosec teamwork cannot be limited solely to the organization or even industry level.

Elastic’s free and open philosophy aims to help infosec teams globally via a community-centered approach to solving security problems. True to this approach, we are making a public repository available for the universal collection, collaboration, and implementation of security detection rules.

In this webinar, we’ll introduce the repo and cover what you need to know to make the best use of this valuable new resource, including:

  • A walkthrough of the security detection rules repo and what it contains
  • An intro to Elastic's approach to threat hunting and detection
  • Getting started, dependencies, and usage best practices
  • Guidelines on how to contribute (creating issues, style, and process)
  • Detection engineering (rule metadata, Elastic Common Schema (ECS), and rule validation)

You’ll hear directly from two Elastic Security experts on the philosophy behind crafting detections and translating attacker techniques into effective rules, including ways to ensure efficacy and add resilience against attacker evasions.

Additional Resources:

立即登记观看

你将会收到一封相关内容的电邮。

MarketoFEForm