Threat Management
We’re building the next wave of tools and methodologies to help security and operations teams detect, understand, and respond to advanced cybersecurity threats and attacks on their infrastructure and in the cloud, with automated threat detection, investigation, and deflection capabilities.
Our work
- ReleaseMarc Stoecklin, Ian Molloy, and Yaron Wolfsthal8 minute read
The thrill of cyber threat hunting with Kestrel Threat Hunting Language
ReleaseXiaokui Shu, Paul Coccoli, Jiyong Jang, and Ian Molloy7 minute readSysFlow: Scalable system telemetry for improved security analytics
ReleaseFrederico Araujo and Teryl Taylor5 minute read
Projects
A cloud-native system telemetry framework that enables the creation of security analytics on a scalable, pluggable open-source platform.
Tech Preview: IBM Security Threat Investigator
Our team's work has been developed into a beta capability for the IBM Cloud Pak for Security. Threat Investigator finds cases that warrant an investigation and automatically starts investigating. It fetches artifacts that are attached to the cases, completes several rounds of data mining and then generates a timeline and MITRE ATT&CK chain graph of the incident.
IBM Solution: IBM QRadar Network Insights
Our innovations in real-time network traffic analysis are regularly incorporated into new capabilities for IBM QRadar Network Insights.