Blueprint: Build the Best in Cyber Defense

Strategy 11: Turn up the Volume by Expanding SOC Functionality

15 snips
Jul 18, 2023
This podcast covers topics such as threat hunting, red and purple teaming, breach and attack simulation, tabletop exercises, cyber deception, and expanding SOC functionality. It emphasizes the importance of proactive approaches in cybersecurity, the value of documentation and processes, and the challenges and considerations in expanding SOC functionality. The speakers also discuss the benefits of threat hunting and red teaming, different testing methodologies for evaluating SOC effectiveness, the importance of tabletop exercises for incident response, and the concept of deception in cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Value of Diverse Experience

  • Threat hunting benefits from diverse experiences rather than just seniority.
  • Combining data, business, and threat knowledge yields powerful hunt outcomes.
ADVICE

Start With Purple Teaming

  • New SOCs should start with collaborative purple teaming.
  • Use purple teaming to improve data collection, detection, and analyst processes before blind testing.
INSIGHT

Purple Teaming Collaboration

  • Purple teaming blends red and blue teams working closely to improve defenses.
  • Definitions vary widely; teams must clarify their own goals and processes.
Get the Snipd Podcast app to discover more snips from this episode
Get the app