­
(Webinar) How To Level Up Your Threat Detection Practice - Dr. Anton Chuvakin & Andrii Bezverkhyi - All Articles - CISO Platform

Is your threat detection practice up to speed? These days, few enterprises have the fundamentals in place to develop and run high quality detections. Improving and sharing detection together is a MUST for defenders, and is the new requirement for speeding up time to detection. The three biggest challenges of threat detection today, what constitutes good vs. bad detections, and insights into how you can level up your enterprise detection and response lifecycle.

  • Learn about the current state of detection and modern detection requirements
  • Good vs bad detection
  • Review the most used detection rules and how they could be improved
  • Seven tips to help you improve your detection rules and response

 

 

About Speaker

Dr. Anton Chuvakin is Googles cyber security industry expert. Anton was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR.

Andrii Bezverkhyi, founder of the worlds largest threat detection marketplace and Founder, CEO and chairman at SOC Prime. Working on Detection as a Code as CI/CD process for masses. Solving the Data Quality problem for cyber. Huge addict and supporter of MITRE ATT&CK and Elastic stack since 2016, taking Sigma to mass market since 2017.

 

 

(Webinar) Recorded

 

 

Discussion Highlights

1. Topics:

  • State of Detection
  • Modern Detection Requirements
  • Better and Faster
  • Detect Your Threats
  • Test and refine on historical data
  • Where are we now
  • How do we get better?
     

2. Are we finally in Balance?

9640957483?profile=RESIZE_584x

 

3. Detection Better Or Faster?

9640961660?profile=RESIZE_710x

4. Detect Your Threats

  • The best threat actors tune their approach for their targets
  • The best defenders do too
  • Can you, though?
  • Get the rules or write them!

5. What is Bad Detection? What is Good?

When you hear "write good detections" what do you actually do?
What about bad detections? Is the bottom of the pyramid bad?

9640974886?profile=RESIZE_400x

6. You say "Do Good detections"

How to make my directions better
Test and refine them
What if I don't have an attacker handy?
Simulate, use historical data etc

7. Correlation 2021

9640996478?profile=RESIZE_710x

8. Learnings On Detection

  • More noisy (higher FP) rules and less noisy rules both have merit and value
  • Rules that do not name a specific threat have merit as well, not all above CVEs
  • The value of many rules is in being an input into another rule (or SOAR)
  • The only way to judge the rule value is with local context 
  • Sometimes the speed of rule development is the main value of the rule
  • Why is correlation dead? What happened here?
  • Some rules nicely achieve what others try to do with ML

9. Threat Bounty Program

9641009655?profile=RESIZE_584x

10. Connecting the global cyber security community

9641010654?profile=RESIZE_710x

11. YARA-L threat detection language

  • Modified Yara for event logs
  • Built for threat detection not data query
  • Write rules that work on modern attacks
  • Embedded in Chronicle's detection engine
  • Apply rules in real time or retrospectively against historical data

12. Run SOC Prime detection rules in Chronicle

  • Covert legacy rules with sigma to YARA-L converter
  • Use 500+ Yara-L based SOC Prime rules in the chronicle Github repository
  • Run detections across all security telemetry in Chronicle
Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (Monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

CISO MeetUp: Executive Cocktail Reception @ Black Hat USA , Las Vegas 2025

  • Description:

    We are excited to invite you to the CISO MeetUp: Executive Cocktail Reception if you are there at the Black Hat Conference USA, Las Vegas 2025. This event is organized by EC-Council & FireCompass with CISOPlatform as proud community partner. 

    This evening is designed for Director-level and above cybersecurity professionals to connect, collaborate, and unwind in a relaxed setting. Enjoy…

  • Created by: Biswajit Banerjee
  • Tags: black hat 2025, ciso meetup, cocktail reception, usa events, cybersecurity events, ciso

6 City Playbook Round Table Series (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    Join us for an exclusive 6-city roundtable series across Delhi, Mumbai, Bangalore, Pune, Chennai, and Kolkata. Curated for top cybersecurity leaders, this series will spotlight proven strategies, real-world insights, and impactful playbooks from the industry’s best.

    Network with peers, exchange ideas, and contribute to shaping the Top 100 Security Playbooks of the year.

    Date : Sept 2025 - Oct 2025

    Venue: Delhi, Mumbai, Bangalore, Pune,…

  • Created by: Biswajit Banerjee

National Insider Risk Symposium, Washington DC, USA 2025

  • Description:

    We are excited to invite you to the 10th National Insider Risk Symposium, a premier forum bringing together leaders and experts from both the commercial and public sectors to address the evolving landscape of insider threats. CISOPlatform is a proud community partner for this event. 

    Event Details:
    Venue: National Housing Center, 1201 15th St NW, Washington, D.C. 20005
    Dates: September 17–18,…

  • Created by: Biswajit Banerjee
  • Tags: national insider risk symposium, ciso, cybersecurity events, usa events