Icon

Simon O’Brien

Speaker

Simon O’Brien

Splunk

@

Simon is the Director of the Global Security Strategist team at Splunk, where he has been helping organisations across the world enhance their security visibility and incident detection capabilities since 2014.

Simon has been an information security professional for close to 20 years, with experience across organisations of all sizes and industries. Simon is a passionate infosec leader, focussing on security architecture, risk management, cloud security and visibility strategies, diversity and empowerment. Simon holds a bachelor’s in information systems, as well as several industry certifications. In recent times, Simon has led Splunk’s ‘Boss of the SOC’ CTF program, taking the blue team targeted CTF to 10’s of thousands of competitors across the globe.

With a focus on decreasing analyst response time, Simon is looking forward to taking this year’s AusCERT attendees through a hands-on workshop focussed on threat simulation and detection engineering. In this hands-on workshop you will learn how to rapidly deploy a preconfigured lab environment with common data sources integrated with Atomic Red Team (ART) using the open source Attack Range tool developed by the Splunk Threat Research Team (STRT). With this environment you will simulate attack techniques from MITRE ATT&CK and understand how to detect such threats using data analytics.

Simon O’Brien @ AusCERT2023