{"id":4383,"date":"2024-07-09T17:22:28","date_gmt":"2024-07-09T22:22:28","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cloud-based-investigations-platforms-target-complexity-incident-response"},"modified":"2024-07-09T17:22:28","modified_gmt":"2024-07-09T22:22:28","slug":"cloud-based-investigations-platform-targets-complexity-in-incident-response","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/09\/cloud-based-investigations-platform-targets-complexity-in-incident-response\/","title":{"rendered":"Cloud-Based Investigations Platform Targets Complexity in Incident Response"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbf389732fa2a756a\/668d6ef0cff58843871d7af5\/Kanpan-cyber-investigations-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Investigating a cybersecurity incident juxtaposes the need for a great deal of expertise with a great deal of grunt work \u2014 and the resulting job can be tough to navigate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Training up hard-to-find cybersecurity experts is necessary to meet the need, but so are better tools to speed up the steps of an investigation, from the initial triage to the resulting report. To that end, startup Command Zero, which launched today, has a stated aim to address the gap by helping companies reduce log-parsing workloads and providing much-needed expert support to investigators.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The goal of Command Zero&#8217;s cloud platform is to give analysts and threat-hunting teams the ability to conduct more consistent investigations more quickly and have the outcomes be more auditable, says Dov Yoran, co-founder and CEO of the Austin, Tex.-based company.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Automation, Simplicity to Reduce Grunt Work\">Automation, Simplicity to Reduce Grunt Work<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Command Zero&#8217;s approach involves a platform that plugs into a company&#8217;s infrastructure, enables different technology modules, and guides the analyst through the investigation, including prompting them with context-dependent questions and pointing them to which data sources might hold the answers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Along the way, it automates many labor-intensive and low-value steps in the investigation process, organizes log information gleaned from an incident, and uses AI to write consistent investigations reports, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cmdzero.io\/blog-posts\/introducing-command-zero\" rel=\"noopener\">a launch announcement on the company&#8217;s site<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The approach allows tier-2 and tier-3 analysts to be quantitatively more efficient, Yoran tells Dark Reading: One team that piloted the platform reduced the average time of an investigation from 4 to 5 hours to 20 to 30 minutes; while another reduced time from 15 minutes using six different tools, to five minutes using the single platform, he said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The whole idea is that we&#8217;ve done lots of this in past lives, and so bringing carefully curated expert knowledge and content into the platform, into the investigations, and to the investigator will dramatically increase their impact,&#8221; he says. &#8220;These [skilled professionals] are the most scarce resources on the enterprise security team.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Filling an Important Skills Gap\">Filling an Important Skills Gap<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Jon Oltsik, analyst emeritus at market intelligence firm Enterprise Strategy Group, agrees that while cybersecurity industry groups <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/white-house-cyber-workforce-strategy-no-quick-fix-for-skills-shortage\" rel=\"noopener\">consistently flag a shortage of skilled experts to fill jobs in the industry,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> the real issue is a shortage of the right kinds of skills \u2014 such as analysts who can investigate incidents effectively.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Investigations often require lots of internal data sources, threat intelligence analysis, and a fair amount of time [and] care,&#8221; he says. &#8220;Investigations and digital forensics are advanced skills that many organizations lack entirely or have minimal resources in this area. Given the preponderance of data breaches and ransomware, organizations know they need improvement in these areas, but most default to service providers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Allie Mellen, a principal researcher in the Security and Risk group at Forrester, notes, &#8220;We do have a talent gap. There are a lot of people that want to get into cybersecurity, but most don&#8217;t have the knowledge and experience required for investigations. They have to learn on the job.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Adding insult to injury, an annual security survey conducted by Forrester Research found that thousands of security managers and leaders identified investigations as the most time-consuming part of the incident-response process, according to Mellen.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Investigating incidents is undoubtedly a major pain point for companies,&#8221; Mellen says. &#8220;The industry often overemphasizes the importance of detection and taking action for response, without considering the big task in the middle: investigation.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Moving Beyond AI for Reports\">Moving Beyond AI for Reports<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Generative AI (GenAI) and large language models (LLMs) promise to make automated investigations systems function better as analysts&#8217; assistants. For his part, Yoran stresses that investigations will always involve human judgment \u2014 AI and machine learning automation can only do so much.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But, while machine learning is increasingly incorporated into products in ways that users may not realize, AI remains largely an overpromised feature, says Forrester&#8217;s Mellen. LLMs, for example, are really good at producing &#8220;a plethora of text &#8230; instead of a concise and visual description&#8221; to explain an incident alert, she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The future of investigations platforms like Command Zero, Mellen says, is the potential to easily pull data from all the devices and log files on a network, using machine learning models to find anomalies, and using GenAI to turn natural language queries into searches and actions.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cloud-based-investigations-platforms-target-complexity-incident-response\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Investigating a cybersecurity incident juxtaposes the need for a great<\/p>\n","protected":false},"author":12,"featured_media":4384,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4383","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloud-based-investigations-platform-targets-complexity-in-incident-response.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4383"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4383\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4384"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}