39:51Blue team 101 – analyses, procédures et astuces pour débuter
Download resourcesAbout this session
Mathieu Hinse, a cyber threat intelligence technical lead at Intact Financial, gives a French-language primer for people starting out in blue team and incident response work. His guiding thread is that every incident boils down to two questions (is it malicious, and how do we fix it for good) and that quality of analysis must always come before quantity of tickets closed, because thorough work reduces recurrence and therefore ticket volume. On the technical side he insists on building a high-level diagram of the security solutions in place, one per scenario such as email or web browsing, so an analyst can reason about which control should have caught a threat and why it did not; he uses a malware-download example to show how a firewall, sandbox not deployed inline, and a disabled IPS rule each let something through. On the management side he covers a service catalogue, planned annual objectives and hands-on technical training with certification. He closes with practical tips: security podcasts, watching offensive demos to learn detection, and disabling PowerShell version 2.
Les menaces et attaques sont récurrentes sur les infrastructures. On tente donc de constamment améliorer nos systèmes afin de détecter et de prévenir les attaques. Mais, est-ce que nos analyses et nos procédures sont vraiment orientées vers ces objectifs? On abordera ce sujet via quelques scénarios, qui ont des degrés de maturité différents, basés sur des cas réels observés. Finalement, quelques astuces pour aider les membres du blue teams dans leurs actions quotidiennes.
Key takeaways
- Build a high-level diagram of your security solutions, one per scenario (email, web browsing, data center), showing which controls a threat passes through and in what order.
- During analysis, ask why a threat was only caught at the last line of defence and which other control should have stopped it, then fix the misconfiguration to cut recurrence.
- Prioritise quality of end-to-end analysis over the raw number of tickets closed; reducing recurrence lowers ticket volume over time.
- Investigate incidents dynamically and over time (host history, prior tickets, what ran just before) rather than as a single static moment.
- On the management side, maintain a service catalogue with a list of partners for gaps, set planned annual objectives, and require hands-on technical training with certification.

