Right as most companies were finally getting used to remote work, the work environment changed once again: many companies now have employees asking to work back in the office, to stay at home or for some form of hybrid option.
This brings up more unique security concerns as companies now have more entry points that outside attacks can target with a multitude of different types of malware. This makes it much harder for the security team to properly identify how the attack got through their defense, and to patch those holes effectively. Thanks to Jamf Protect, we can now get alerts when these types of attacks present themselves, but without knowing what caused the security breach leading to the attack, there is no way to effectively prevent the same issue from occurring again.
In this session, I will walk through how to create a “cause analysis workflow” using a combination of Jamf Pro, Jamf Protect, Splunk (SIEM product), Slack, DepNotify and Aftermath (open-source incident response tool), which will present a map they can use to find the source of the problem and fix it at its root.
This brings up more unique security concerns as companies now have more entry points that outside attacks can target with a multitude of different types of malware. This makes it much harder for the security team to properly identify how the attack got through their defense, and to patch those holes effectively. Thanks to Jamf Protect, we can now get alerts when these types of attacks present themselves, but without knowing what caused the security breach leading to the attack, there is no way to effectively prevent the same issue from occurring again.
In this session, I will walk through how to create a “cause analysis workflow” using a combination of Jamf Pro, Jamf Protect, Splunk (SIEM product), Slack, DepNotify and Aftermath (open-source incident response tool), which will present a map they can use to find the source of the problem and fix it at its root.