banner.jpg
On-demand Webinar
LP1.png

Every security incident brings a lesson. But without the proper tools in place, security analysts are left having to learn the same lesson every time an incident occurs, spending just as much time as they did when the first incident took place.

In this webinar, SANS Instructor Jake Williams joins SECDO Cybersecurity Engineering Leader Joseph Pizzo to show how leveraging behavior-based indicators of compromise (BIOCs) can automate incident response to ensure your security workflow takes advantage of lessons learned. 

Attendees will learn: 

  • What are BIOCs and how they work

  • The importance of thread-level visibility into endpoint activity to thoroughly identify BIOCs in the enterprise
  • How to create, configure, and run rules to detect BIOCs
  • What the proper incident response action should be for common BIOCs

WATCH THE WEBINAR