article thumbnail

Does the World Need Cloud Detection and Response (CDR)?

Anton on Security

Second, a hypothetical CDR tool will need to do its own threat detection, enable the analysts to triage alerts, support incident investigative workflows and probably do some response automation too. However, there are already tools that do all these things, but perhaps not all at once and not focused on the cloud.

article thumbnail

Threat-informed or Threat-owned? Classic Practices Will Probably Save You!

Anton on Security

At some point, a “pre-owned” (compromised before you ever saw it) email security appliance , firewall, or a piece of software will show up in your environment (you no longer need to be this elite for it; it ain’t 2013). You will not detect this , in all likelihood. This means you need to detect whatever the attacker does later on.

Firewall 130
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Today, You Really Want a SaaS SIEM!

Anton on Security

The mission also evolved a lot over the years from alert aggregation to compliance and reporting to threat detection and response support. To remind, the mission that the SIEM is aimed at is very difficult in today’s environments.

article thumbnail

RSA 2023: Not Under the GenAI Influence Yet!

Anton on Security

Ultimately, this is where detection and response money is. A few booths actually had “TDIR” on them which stands for Threat Detection, Investigation and Response. Another lesson: CSPM may be “so 2013” but in 2023, most people seem to start their cloud security tool journey with the posture assessment, just as before.

article thumbnail

Does the World Need Cloud Detection and Response (CDR)?

Security Boulevard

Second, a hypothetical CDR tool will need to do its own threat detection, enable the analysts to triage alerts, support incident investigative workflows and probably do some response automation too. Related blog posts: “How to Think about Threat Detection in the Cloud”. Who Does What In Cloud Threat Detection?”.

article thumbnail

Debating SIEM in 2023, Part 2

Anton on Security

And please don’t say “because you are still SIEM-less” or “because you didn’t buy it in 2003, 2013, 2020, etc.” So let’s dive into this! Let’s start with this: why should anyone buy an SIEM tool in 2023? You are not taking aspirin because of low aspirin content in your blood (as my boss of many jobs ago used to say).

article thumbnail

Today, You Really Want a SaaS SIEM!

Security Boulevard

The mission also evolved a lot over the years from alert aggregation to compliance and reporting to threat detection and response support. Here are some arguments: Likely YES: You are “cloud first” or as Gartner says now “cloud smart” (because “cloud-first is so 2013”). seconds per any search).