What an ex-NSA red teamer wants every SOC to stop doing
The New Stack Carly Page
Security operations centers are overwhelmed with alerts from multiple data sources, creating alert fatigue that obscures genuine threats amid noise. The webinar on July 23 will feature Chas Clawson, an ex-NSA Red Team member now at Sumo Logic, discussing how to reduce alert volume through better context and data strategy. Teams should shift from individual event-based alerts to entity-centric detections around users and workloads, with AI helping to correlate evidence and surface high-priority signals rather than replacing human analysts.
Why it matters
Security teams have spent years trying to see more. More endpoints, more cloud services, more identities, more telemetry. For the The post What an ex-NSA red teamer wants every SOC to stop doing appeared first on The New Stack.