Magnets for Needles in Haystacks: Using MITRE ATT&CK w/ Risk-Based Alert | Haylee Mills | WWHF 2023 @WildWestHackinFest
Magnets for Needles in Haystacks: Using MITRE ATT&CK w/ Risk-Based Alert | Haylee Mills | WWHF 2023  @WildWestHackinFest
Uploaded June 2024 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com

MITRE ATT&CK helps us identify threats, prioritize data sources, and improve security posture, but how do we actualize those insights for better detection and alerting? We shift to alerts on aggregated behaviors over direct alerts, and make our noisy datasets into valuable treasure troves tagged with ATT&CK metadata. Let's discuss the key features needed to implement this in any security toolset!

“Haylee went to school for 2D animation and worked in that industry for four years before 80 hour weeks and 40 hours of minimal pay crushed her soul and her dreams. During her quarter-life crisis living with her parents, she bicycled across the United States and dabbled in documentary film-making, aquaponics, and urban gardening. She ultimately wandered into information security as a career path thanks to a friend in the field who believed in her and dangled the starting pay for an information security analyst. Beyond the money, she quickly developed a passion for the craft as well as building pipelines for folks to achieve financial stability in this career.

She started as a SOC analyst working crappy alerts, made better alerts and an elegant investigation workflow in Splunk with Risk-Based Alerting as a Content Engineer, and finally moved to Splunk to evangelize and advise on RBA as a Security Strategist. In that time, she hosted regular classes with mentees and created a course on Twitch/Youtube to reach people interested in cybersecurity without a background in IT or Computer Science. In her spare time (lol), she works with the Cybersecurity Council of Arizona building infosec education pipelines, as social media staff for AZ’s premiere cybersecurity conference CactusCon, and on the Tempe Arts & Culture Commission to advise the City on arts development and preservation.”

///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
Magnets for Needles in Haystacks: Using MITRE ATT&CK w/ Risk-Based Alert | Haylee Mills | WWHF 2023Lessons Learned in a Year of Social Engineering | Alice ThorneThe Human Vulnerability: Social Engineering in a Hyper Connected World | David BoydMile High 2026 | Sponsor Interview CompilationSocial Engineering My Way Into Conferences | Frank TrezzaBeyond the Malware: Dissecting Info Stealers Infection Vectors, Stolen Assets and CountermeasuresAttacking SCCM with SCCMHunter | Garrett FosterPacket Generation with Scapy | Bill StearnsA Fistful of Headers: Taming the Wild Web at Scale | Cary Hooper and Wesley McElhinnyNot Doomed...Yet | Chloé MessdaghiThe Role of Pentesting and Continuous Validation | Dan DeCloss | WWHF 2023A Post Incident Case Study for SMB Response Teams | Amanda Berlin
Wild West Hackin Fest |

Magnets for Needles in Haystacks: Using MITRE ATT&CK w/ Risk-Based Alert | Haylee Mills | WWHF 2023

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER