Hurricane Labs Reduces Noisy Alerts Using GreyNoise

Summary

Hurricane Labs has brought together a team of Splunk ninjas who are second-to- none in managing ES and Phantom deployments on behalf of their customers. Yet like any team managing a complex security environment, they would see their alert volumes grow, overwhelming their analysts as they added more detections and new customers. They had a choice: hire more analysts or figure out a way to reduce the number of alerts. This was when Hurricane Labs' Director of Managed Services decided to take a look at GreyNoise, a source of “anti-threat intelligence” that tells security teams which alerts NOT to worry about.

Hurricane Labs has brought together a team of Splunk ninjas who are second-to- none in managing ES and Phantom deployments on behalf of their customers. Yet like any team managing a complex security environment, they would see their alert volumes grow, overwhelming their analysts as they added more detections and new customers. They had a choice: hire more analysts or figure out a way to reduce the number of alerts. This was when Hurricane Labs' Director of Managed Services decided to take a look at GreyNoise, a source of “anti-threat intelligence” that tells security teams which alerts NOT to worry about.

Read the transcript