CYBERWOX

Detection Opportunities

Detection Opportunities is a podcast for security professionals who care about building resilient detection and response systems. Each episode explores real-world attacks, breaks down how signals become insights, and dives into the engineering mindset behind effective threat detection, investigation, and defense. Grounded in frontline experience across SIEM development, security operations, incident response, and threat hunting, this show brings a practical, systems-level lens to modern security engineering.

Koniecznie odwiedź stronę podcastu i wesprzyj twórcę: podcasters.spotify.com

Autor

CYBERWOX

Kategoria

Technology

Strona podcastu

podcasters.spotify.com

Ostatni odcinek

6 cze 2025

Gdzie słuchać?

Podcasty w aplikacji Replaio Radio Już wkrótce

Podcasty trafią do aplikacji już wkrótce. Zainstaluj teraz i jako pierwszy zobacz nowe podejście do podcastów

Pobierz z Google Play Zainstaluj za darmo Android prawie 10 mln pobrań · ocena 4,8 iOS niedługo

Odcinki

Detection-as-Code & CI/CD in Detection Engineering with Dennis Chow | EP. 9 06.06.2025

Detection as Code is one of the most important evolutions in modern security detection, and in this video, we break it down. I first encountered this concept as a Cloud Threat Detection Engineer at Datadog. Today, I’m joined by Dennis Chow, a Detection Engineering specialist and author of Automating Security Detection Engineering (which I had the honor of technically reviewing). Together, we explo...

Applying AI, LLMs & Prompt Engineering for Threat Detection with Dylan Williams | EP. 8 29.04.2025

Visit my ⁠sponsor⁠ to view the current average annual salary for a Cybersecurity degree and learn how to get started. I had the pleasure of hosting Dylan Williams and we explored how AI can be applied in cybersecurity, focusing on threat detection. We also examined how his project, D.I.A.N.A., turns threat intelligence reports into actual detections. Connect with Dylan Dylan's Resource on Applying...

Get-RoleGroup - Detecting Attacker Enumeration in Microsoft 365 Exchange with Purav Desai | EP. 7 29.04.2025

Visit my sponsor to view the current average annual salary for a Cybersecurity degree and learn how to get started. ⁠Purav's LinkedIn⁠ ⁠Deciphering UAL Exchange Admin Audit Logging Office365 Management Activity API Connect-IPPSSession _____________ TIMESTAMPS: 00:00 Intro 00:36 Get-RoleGroup Operation 01:37 Enumeration is not logged?? 05:53 SNHU 07:22 Using the Security Compliance Center EOPCmdlet...

Add-RoleGroupMember - Detecting Persistence in Microsoft 365 Exchange with Purav Desai | EP. 6 29.04.2025

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder. In today's episode, we explore the Add-RoleGroupMember operation in Exchange Online. Purav's LinkedIn Deciphering UAL Microsoft Application IDs Permission Alert Policy _____________ TIMESTAMPS: 00:00 Intro 00...

New-RoleGroup - Detecting Privilege Escalation in Microsoft 365 with Purav Desai | EP. 5 29.04.2025

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder. ⁠Purav's LinkedIn⁠ ⁠Deciphering UAL⁠ ⁠Learn about auditing solutions in Microsoft Purview⁠ _____________ TIMESTAMPS 00:00 Intro 00:20 Deciphering New-RoleGroup 09:06 Key Fields 10:11 Deciphering with Exchange...

Microsoft 365 Forensics & Incident Response with Purav Desai | EP. 4 29.04.2025

Learn how to decipher the Microsoft Unified Audit Log (UAL) from a Digital Forensics & Incident Response (DFIR) perspective with Purav Desai, an experienced M365/Azure Incident Responder. Purav's LinkedIn Deciphering UAL Learn about auditing solutions in Microsoft Purview _____________ TIMESTAMPS 00:00 Intro 00:49 Microsoft 365 Auditing 04:43 The Deciphering UAL Project 07:55 Accessing Purview...

Attack & Detection of a Cloud Security Breach with 0xd4y | EP. 3 29.04.2025

This episode covers an attack scenario very similar to the one that led to the breach of US Bank Capital One.  @0xd4y  goes over the attack scenario using CloudGoat by Rhino Security Labs, and I detect his activities using AWS CloudTrail Lake. _____________ 🧬 VIDEO RESOURCES 🔹 Segev's YouTube Channel:  @0xd4y  🔹 Segev's walkthrough 🔹 Former AWS engineer convicted over hack that cost Capital On...

The Anatomy of a Google Cloud (GCP) Cryptomining Attack | EP. 2 29.04.2025

GCP Service Accounts are interesting cloud identities. Let's review how they contributed to a Cryptocurrency Mining Attack in this Case. _____________ 🧬 EPISODE RESOURCES 🔹 How A Compromised AWS Lambda Function Led to a Phishing Attack 🔹 GCP Lateral Movement & PrivEsc 🔹 GCP Service Accounts 🔹 DEFCON 30 Cloud Village - Weather Proofing GCP Defaults 🔹 GCP IAM basic and predefined roles ref...

How A Compromised AWS Lambda Function Led to a Phishing Attack | EP. 1 29.04.2025

In this video, I’ll be going over detection opportunities at various stages of cloud security attacks. Compromised Cloud Compute Credentials: Case Studies From the Wild _____________ TIMESTAMPS 00:00 Intro 00:40 The Attack Case 02:12 The Attack Graph 02:44 The Attack Flow 03:06 Detection Opportunity 1: Enumeration/Reconnaissance/Discovery - Cloud Infrastructure Discovery 05:27 Detection Opportunit...

Słuchaj podcastu Detection Opportunities w Replaio

Radio i podcasty w jednej aplikacji - za darmo, bez zakładania konta. Zainstaluj już dziś i nie przegap premiery

Pobierz z Google Play

Replaio nie jest wydawcą podcastów; nazwy audycji, okładki i audio należą do ich autorów i są rozpowszechniane przez publiczne kanały RSS