Mitchell Bezzina

257 posts

Mitchell Bezzina

Mitchell Bezzina

@MitchellBezzina

Sr Dir. of Marketing, Security Services @PaloAltoNetworks All opinions are my own

California, USA Katılım Kasım 2014
98 Takip Edilen99 Takipçiler
WHEEL 🅿️rodz.
WHEEL 🅿️rodz.@458Piloti·
Been 2 months since I gave out a World Championship. I kinda feel guilty, but the £1 Million make up for it.
English
136
64
897
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
@CroftyF1 Shouldnt Mercedes be fined as well when they decided to use the design that they previously gave/sold to RacingPoint? Surely some responsibility falls to them as bit teams using them what made it illegal. Speaking impartially. Thanks for a great show & team @SkySportsF1
English
0
0
0
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
@EricSkinner @Pfirstbrook @ianmcshane Agreed, XDR lets us step away from data sources and is an opportunity to focus on analyst outcomes. Alerts and Logs in SIEM lack context, N/EDR has context from that source but lacks the rest. Enter XDR that brings it all together for unknowns & SOAR to automate known ops process
English
0
1
3
0
Eric Skinner
Eric Skinner@EricSkinner·
@Pfirstbrook It's a different problem set from SIEM/SOAR for the reasons you describe, but not necessarily a smaller problem. XDR needs to deliver more by leveraging the deeper data view it gets. As @ianmcshane says, "more context with quality data." Email and network visibility can enrich.
English
2
1
3
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
@josh_zelonis Could go the reverse as well :) this is why its such a great conversation, glad your leading this
English
0
0
1
0
Josh Zelonis
Josh Zelonis@josh_zelonis·
I'm claiming analyst privilege on XDR: 1) The acronym is Extended Detection & Response 2) Fully formed XDR capabilities are vendor agnostic and do detection on application, endpoint, and network telemetry. 3) If this sounds like a SIM use case it's because this is not new.
English
6
11
42
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
@josh_zelonis Thats fair, but I think itll be hard to draw the line? If you add the Application context, what about Containers, PaaS, IaaS, IOT, etc... Might be a slippery slope. I think we should find the uber classifications, we chose Network, Endpoint and Cloud which is an option
English
1
0
0
0
Josh Zelonis
Josh Zelonis@josh_zelonis·
@MitchellBezzina I would argue that in order to do detection well you first have to collect data, and then you need to classify or contextualize it. This is a lot easier to do when observing behavior at the same level it's occurring.
English
1
0
1
0
Eric Skinner
Eric Skinner@EricSkinner·
@josh_zelonis @maximweinstein One of the things that’s different between XDR and SIEM (most of the time, for now) is that XDR (just like EDR) sees full activity telemetry, not just alerts. XDR does (or leverages) full EDR-style activity recording, on endpoints and more.
English
2
1
1
0
Mitchell Bezzina retweetledi
Josh Zelonis
Josh Zelonis@josh_zelonis·
There's enough companies branding their EDR+ solutions XDR I think it's a thing now.
English
2
3
7
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
Attackers exploit vulnerability on the remote code execution flaw (CVE-2018-0171) in Smart Install function of Cisco switch hubs.ly/H0bCJ260
English
1
0
1
0
Mitchell Bezzina
Mitchell Bezzina@MitchellBezzina·
Alternative communications planning and cybersecurity incident response - what to do if a data breach compromises corporate email servers hubs.ly/H0bCH3l0
English
0
0
0
0