Dec. 15, 2023, 10:13 p.m. | SANS Offensive Operations

SANS Offensive Operations www.youtube.com

Over the past few years we've seen an expansion in both the variety of canaries and the locations to hide those canaries in the cyber deception realm. What we've yet to see is refinement in the implementation of those canaries to evade discovery from wary attackers.

For blue teams, properly tuned SIEM rules utilizing deception canaries are higher fidelity and lower volume alarms. This means that most of the time when the alarm fires it indicates a true positive. This …

attackers blue blue teams cyber cyber deception deception discovery evade expansion hide implementation realm rules siem teams

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Specialist, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

Principal Security Researcher (Advanced Threat Prevention)

@ Palo Alto Networks | Santa Clara, CA, United States

EWT Infosec | IAM Technical Security Consultant - Manager

@ KPMG India | Bengaluru, Karnataka, India

Security Engineering Operations Manager

@ Gusto | San Francisco, CA; Denver, CO; Remote

Network Threat Detection Engineer

@ Meta | Denver, CO | Reston, VA | Menlo Park, CA | Washington, DC