While at CiscoLive, I had an opportunity to chat with Jim McCarthy about TDIR (Threat Detection Investigation and Response) and how it is shifting the way we look at security. Jim gives us details on:
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
Hey everybody, we’re out here at Cisco Live and I ran into Jim here and you’re in Splunk education and we’ve been talking about TDIR. Educate us on what that means. What does it do? >> It’s good to see you man. Uh four phases, right? So we want to take detections and modernize them against our adversaries who are using AI to attack us at scale. So we have to adjust and shift into behavioralbased detections instead of finding based detections that are just solely looking for a single event. uh the traditional detection models are not ready for AI attacks. We’ve got to get ready now. I think it also means structuring and managing your data effectively so that you can scale as you take on these behavioral models and you start doing behavioral detections because that does mean more back-end data uh you know and then dev sec ops treating our content as code whether it’s a detection whether it’s a visualization a dashboard an app we can treat it like code we can version it we can test it you know everyone’s favorite job uh and then finally I think the biggest shift is integrating all of this into your business life cycle making it part of how you develop systems, how you develop applications, scanning for problems before they ever get to the sock, right? Reducing the friction around analysts is automation’s responsibility, but our responsibility as good technologist is ensuring that fewer issues ever reached in the first place. >> Yeah. And as far as Splunk’s approach to DDI, kind of what are some of the tools and technologies that we use there? >> Oh, absolutely. So, Splunk Enterprise Security, right? It’s our number one bestselling premium app and add-on, I believe, to this day. Um the unified timeline I think is what gives analysts confidence to make decisions because they’re not looking at isolated fragmented data. They can see one clear picture of what’s happening in the new IR and uh work it out from there. >> That’s really great. Now if I want to go get educated myself on more of this what we’re talking about today, what should I do? >> Splunk.com/education. There’s tons of free e-learning. There’s also paid e-learning that happens with labs, uh, ILTs, Vilt, Splunk, Lantern articles. You name it, we’ve got it, it’s there. That’s really great, man. I appreciate your time today, Joe. >> Thanks so much, man.