Blueprint: Build the Best in Cyber Defense

Strategy 7: Select and Collect the Right Data

4 snips
Jun 19, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Optimize Data Storage by Use

  • Keep data based on how it will be used: hot storage for immediate monitoring, cheaper archive for forensic use.
  • Prioritize accessibility according to expected usage patterns to optimize cost and response time.
ADVICE

Collect CRUD and Login Data

  • For cloud or application logs, focus on collecting CRUD operations plus logins and administrative actions.
  • This minimal data gives a practical and effective foundation for incident investigation.
INSIGHT

Types of Detection Signatures

  • Detection rules consist mainly of signature-based or behavioral/anomaly-based types.
  • Behavioral rules need context to reduce false positives, especially for identity and timing anomalies.
Get the Snipd Podcast app to discover more snips from this episode
Get the app