Mastering Post-Breach Response with Tanium - Tanium Tech Talks #107
Industry data says 50% of cyber attacks are from external sources that bypassed your defenses. How do you respond?
EDR is a great start. Then what?
What is the cost of downtime in your business?
How long do you wait on data during an incident?
Find out in this episode why Tanium is the best platform for incident response in the industry.
#informationsecurity #informationtechnology #dfir #incidentresponse #infosec
RELATED EPISODES
Investigate https://www.youtube.com/watch
Guardian https://www.youtube.com/watch
Endpoint Reactions https://www.youtube.com/watch
THR IRL Threat Response In Real Life https://www.youtube.com/watch
CHAPTERS
00:00 Intro
01:38 Meet Thomas
02:20 Where did you get this idea?
03:08 What surprised you?
04:10 Not if but when
04:52 DATA: Vulnerability
06:27 DATA: Exploits vs IOCs
08:04 DATA: How incidents are discovered
09:15 Incident Response workflow
11:03 NotPetya example
12:35 IR speed vs data wait time
14:51 Tanium platform
15:40 Threat Response capabilities
17:20 Attack disruption with response actions
20:07 Tanium Guardian
21:06 Tanium Impact
22:09 Tanium Investigate
23:28 Takeaways
24:44 Resources