
2020-004-Marcus Carey, ShmooCon Report, threat simulation
Mrs_Marong💞
Description
<p> </p> <p><span style="font-weight: 400;">Marcus Carey</span> <a href= "https://twitter.com/marcusjcarey"><span style= "font-weight: 400;">https://twitter.com/marcusjcarey</span></a><span style="font-weight: 400;"> </span></p> <p><span style="font-weight: 400;">Prolific Author, Defender, Enterprise Architect at ReliaQuest</span></p> <p><a href="https://twitter.com/egyp7"><span style= "font-weight: 400;">https://twitter.com/egyp7</span></a><span style="font-weight: 400;"> </span></p> <p><a href= "https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950"> <span style= "font-weight: 400;">https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950</span></a></p> <p> </p> <p><span style="font-weight: 400;">“GreyMatter integrates security data from security incident and event manager (SIEM), endpoint detection and response (EDR), firewalls, threat intelligence feeds, and other security tools, and includes analysis functions and automation. Threatcare's technology — which will become a new feature on the platform — simulates how a specific threat or attack could target an organization's network in order to determine whether its security tools and settings are or are not actually working to thwart the threats.”</span></p> <p> </p> <p><span style="font-weight: 400;">Security model - everyone’s is diff</span></p> <p><span style="font-weight: 400;"> </span> <span style="font-weight: 400;">How do you work with your threat model?</span></p> <p><span style="font-weight: 400;"> </span> <span style="font-weight: 400;">A proper threat model</span></p> <p> </p> <p><strong>Attack Simulation - </strong></p> <p><span style="font-weight: 400;"> </span> <span style="font-weight: 400;">How is this different from doing a typical Incident Response tabletop? Threat modeling systems?</span></p> <p><span style="font-weight: 400;"> </span> <span style="font-weight: 400;">How is this different than a pentest?</span></p> <p><span style="font-weight: 40