Breaching the Gap: Tanium + OpenCTI + OpenBAS for Actionable Intelligence with Attack Simulation
This lab will cover the Tanium integration with Filigran, an open-source extended threat management suite, to ingest threat reports applicable to an organization, pass those observables into Threat Response for detection, and execute an attack simulation to validate security controls. Following the simulation, this lab will explore the ability within Threat Response to highlight the gaps in existing EDR capability to identify all the stages of a Breach Attack Scenario. Pre-Req(s): Practical understanding of Tanium Threat Response, Basic understanding of Threat Intelligence, Basic concept of a Breach Attack Simulation Platform
Lab Outline
Additional details:
Session Tag
Endpoint Management, Tanium Core
Session Type
In-Person, Lab
Modules
Reporting, Threat Response
Difficulty
Intermediate-Advanced