SecOps Forum
SecOps Forum

SecOps Forum emphasizes the integration of Security Operations (SecOps) processes. It highlights real-time threat monitoring, incident response, and shares the application of automated tools to enhance the efficiency of security operations.

TIME & LOCATION
  • 5/15 (Wed.) 14:00 - 17:00 | 701B Meeting Room
AGENDA
5 / 15
14:00 - 14:30
DM Wang / Project Manager, Incident Response TeamT5

Incident response requires thorough preparation and planning. In this session, we'll explore real-life cases to consider whether threats can be analyzed and detected in a timely manner before a security incident occurs and also discuss strategies to enhance cybersecurity resilience.

    5 / 15
    14:45 - 15:15
    NotSurprised / Core Member UCCU Hacker

    This talk will discuss the hardening issues encountered by enterprises, and extend the discussion of international regulations and demand differences derived from supplychain audits.

    • Blue Team
    • Security Operation
    • Policy Management
    5 / 15
    15:45 - 16:15
    Chandler Hsieh / Technical Director Kaspersky Lab Taiwan
    • Threat Intelligence
    • Security Consulting
    5 / 15
    16:30 - 17:00
    Tim Yeh / Security Solution Architect AWS Taiwan

    In the process of incident response, the cybersecurity blue team often needs to conduct a large amount of analysis, including extensive log analysis for cloud events. This presentation mainly shares how to use open source tools for analysis. This includes the mention of SOF-ELK, the open-source forensics project by SANS utilizing Elasticsearch, the use of Graylog + OpenSearch for SIEM analysis, and ways to quickly analyze malicious logs by incorporating established Sigma Rules and other blue team knowledge.

    • Cloud Security
    • SIEM
    • Blue Team