Rémi Langevin

Threat Hunter

Retour à la liste des conférenciers et sessions

Rémi Langevin Threat Hunter,

Rémi has been working in a blue team for a few years as a threat hunter and developper.

He also thinks that tab could be a great indentation character but everybody's using spaces. As such it is more practical to use spaces.


Discussion: Q&A Detection

This is a Q&A session. Moderators will take audience questions both remotely and on-site via sli.do.


Q&A Panel for the detection block

Talk: Willy Wonka and the Detection Factory: Detection Engineering without Alert Fatigue

Talks will be streamed on YouTube and Twitch for free.


"Surely we can make a detection for when the whoami command is executed, right? Nobody ever runs whoami but threat actors." - Someone with no experience in detection engineering

In this talk, we'll discuss how we addressed the dilemma between detection coverage and alert fatigue in a SOC by correlating minor or noisy detection logics. We'll go through our journey to build a custom platform that leverages the concept of indicators. We'll share the toolset and some implementation details and show how we use it to monitor tens of thousands of endpoints. It has become one of our main tools for threat hunting and is used by our SOC analysts to assist them in their investigations.