Breaking the SIEM Confinement @FIRSTdotorg
Breaking the SIEM Confinement  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 1 hour ago
Anthony Talamantes (Johns Hopkins University Applied Physics Laboratory, US), Todd Kight (Johns Hopkins University Applied Physics Laboratory, US)

Anthony has over 24 years of experience in cybersecurity and the last 17 years focused on nation state and sophisticated adversaries. Anthony developed the Cyber Hunt program at Johns Hopkins Applied Physics Laboratory and current manages the Cyber Hunt, Applied Cyber Research, and Architecture & Engineering.

Todd has over 12 years of experience in cybersecurity and is the Lead Cyber Analyst on the Applied Cyber Research team at Johns Hopkins Applied Physics Lab. Todd leads the end point behavioral analysis and uses behavioral patterns to proactively hunt for malicious activity in the enterprise.
--
The focus of this presentation is exploring the limitations of traditional SIEMs and how we have engineered solutions around these limitations at Johns Hopkins University Applied Physics Laboratory. SIEM's are designed for a single query and basic correlation and using the returned data becomes problematic, especially if there are thousands of results or more. These common approaches in SIEM's are often impossible techniques to use to identify sophisticated adversaries. We will illustrate how we use our SIEM, PowerShell, Python, SQL, SOAR, and other methodologies to create and combine more complex analytics that is impossible to complete in any existing SIEM.
Breaking the SIEM ConfinementHunting Cyber Threat Intelligence on TelegramCyber Deception 2.0: Adaptive Honeynets and Canary Intelligence in ProductionWhats New in CSAF v2.1: Key Updates ExplainedArcana: A Unified Framework for Incident Response Documentation and Knowledge ManagementFrom Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic Malware
FIRST |

Breaking the SIEM Confinement

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER