전 NSA 레드팀원이 SOC에서 중단해야 할 사항을 제안합니다.
보안 팀은 다양한 엔드포인트와 클라우드 서비스, 아이덴티티, 텔레메트리 등을 파악하려고 노력하고 있습니다. 그러나 전 NSA 레드팀원은 이러한 접근 방식이 SOC에 경고 피로를 초래할 수 있다고 강조합니다. SOC가 중단해야 할 관행에 대한 통찰력을 제공합니다.
An ex-NSA red teamer suggests what every SOC should stop doing.
Security teams have focused on gathering more data from endpoints, cloud services, identities, and telemetry. However, an ex-NSA red teamer highlights that this approach can lead to alert fatigue in SOCs. Insights are shared on practices that should be stopped to improve security operations.