Loading…
BSidesSF 2023 has ended
Sunday, April 23 • 3:00pm - 5:00pm
IR Workshop

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Event locked in Sched to limit confusion. See registration to determine current session availability.
YOU ARE REQUIRED TO REGISTER AT https://bsidessf.regfox.com/2023 TO ATTEND THIS WORKSHOP (i.e. this session cannot be reserved with Sched)
-----
Today's DevOps world has new responsibilities added to the everyday engineer's existence. A developer often has to assist in incident response and threat hunts. Unfortunately, these skills are hard to learn and can come at a cost if they are done on the job during an event. TableTop/Online Workshop
-----
Today's DevOps world has several new responsibilities added to the everyday engineer's existence. For example, a developer must often assist in incident response and threat hunts. Unfortunately, these skills are hard to learn and can come at a cost if they are done on the job while an event is ongoing.

In this two-hour tabletop/workshop, we will examine a scenario where we are running multiple AWS services and being attacked by an outside threat. Exploring the use of a SIEM (Security Information and Event Management), we will demonstrate how it exposes critical related data to signal errant activity. After the workshop, the participant will come away with a topical understanding of the risks in any cloud deployment, incident response experience, and hands-on experience in using a SIEM and how to integrate it into your observability portfolio. We will leave the online lab portion of this workshop open after the workshop ends to give everyone more time to work independently.

Requirements:
Laptops

Speakers
avatar for Nathan Case

Nathan Case

Ciso, Corsha
Nathan Case is a successful executive and builder, pushing for change in security and the culture surrounding it. Leading strategic initiatives and the creation of new technologies in the healthcare, information technology and cloud industries, focusing on security. A passion for... Read More →


Sunday April 23, 2023 3:00pm - 5:00pm PDT
AMC Theatre 10