I followed SIEM and SOAR events into packet captures, process trees and host, network, cloud and SaaS records. I used timelines and frequency analysis to assess suspicious activity and explained the supported root cause, impact and remediation to the client.
Viewed
Growing MSSP with Offensive Services
Moving from an alert to a response decision
Leading SOC shifts across 150+ client environments
Return to the full story ←