4/16 (Wed.) 14:00 - 14:30 4F 4C

The Last Mile of Blue Team Detection: Integrating Detection Engineering for Threat Detection

In response to the increasingly complex and changing network threats, enterprise networks often exhibit high heterogeneity with diverse architectures, operating systems, and applications. This diversity challenges the application of a single detection logic. Detection Engineering has emerged as a crucial theme, enabling the design of flexible detection rules tailored to specific environments through systematic methods. By abstracting attack behaviors into characteristic patterns, this approach remains adaptable to rapid changes. This presentation explores the core concepts and practices of Detection Engineering, demonstrated with real-world cases. We'll also discuss using frameworks like MITRE ATT&CK to deconstruct and locate potential detection points in attack behaviors.

Mars Cheng
SPEAKER
TXOne Networks Inc.
Senior Threat Research Manager, PSIRT and Threat Research
Dexter Chen
SPEAKER
TXOne Networks Inc.
Threat Researcher, PSIRT and Threat Research

TOPIC / TRACK
SecOps Forum
Live Translation Session

LOCATION
Taipei Nangang Exhibition Center, Hall 2
4F 4C

LEVEL
General General sessions explore new cybersecurity knowledge and non-technical topics, ideal for those with limited or no prior cybersecurity knowledge.

SESSION TYPE
Breakout Session

LANGUAGE
Chinese
Real-Time Chinese & English Translation

SUBTOPIC
Threat Detection & Response
Security Operation
Blue Team