Tapping the 'Visibility Triad'
Extrahop's Matt Cauthorn on Improving Threat Hunting, Incident ResponseNetwork detection and response, endpoint detection and response, and SIEM are the "visibility triad" of critical data sources for effective threat hunting and incident response, says Matt Cauthorn of Extrahop, who explains why.
See Also: 4 Key Elements of an ML-Powered NGFW
In a video interview at Information Security Media Group's recent Cybersecurity Summit in New York, Cauthorn discusses:
- Why each of those three data sources are so critical for threat hunting and incident response;
- The newest frontier in incident response and threat hunting;
- Measuring the effectiveness of threat hunting.
Cauthorn is vice president of security at Extrahop, where he is responsible for all security implementations and leads a team of technical security engineers who work directly with customers and prospects. Previously, he was a sales engineering manager at F5. He began his career as a practitioner, overseeing application hosting, infrastructure and security for five international data centers.