OpenSec: Visual Threat Hunting with Graphviz

Ryan Nolette is a security technologist and threat Hunter at Sqrrl Data, which markets software for big data analytics and cyber security. In this lightning talk, Ryan gives an overview of the threat hunting process, and recommends visualization methods that expedite the process.

Ryan begins the discussion by showing what the process is currently like without visualization; it is monotonous, tedious and inefficient. By recognizing that humans are visual beings and naturally attuned to finding patterns, Ryan demonstrates how utilizing a visualization tool can save both money and time for security professionals.

It is clear that humans are visual learners, and Ryan puts together a very cohesive lightning talk that puts this into persecutive in a security context. By eliminating the tedious and repetitive actions, security professionals can find threats in a fraction of the time compared to conventional log crawling methods.