Threat hunting in plain English (with the SQL to prove it)
Webinar
A public exploit now appears in about a day, down from 150 days three years ago. Attackers move in hours. Most teams still answer in days, because the slow part was never the data sitting on your devices. It's turning a question into the right query, against the right hosts, in a form you can act on.
This session shows a faster path. Ask a question in plain language and watch Fleet turn it into a real osquery scan across every host you manage. Dhruv Majumdar, Fleet's VP of Security Solutions, will run it live, including the case that tests your tooling most: a public exploit with no CVE assigned yet, where a scanner returns nothing and you hunt by artifact instead. The catch most tools get wrong is that you don't hand over control of your environment to get the convenience.
What You'll Learn
- How to answer "which hosts are exposed, and which team owns them" in minutes instead of a ticket, a curl loop, and 90 minutes
- How to hunt by artifact when there's no CVE to match yet, the moment scanners go blind
- Why read-only queries, human-approved changes, and visible SQL are what make this safe to run in production
- How Fleet keeps your RBAC and data where they are, instead of asking you to surrender control to a black box
Speakers
-
Keith Ward Webinar Moderator Future B2B
-
Erin Miska Product Marketing Fleet Device Management
-
Dhruv Majumdar VP of Security Solutions Fleet Device Management
REGISTER NOW & YOU COULD WIN
A $250 Amazon.com Gift Card!
Must be in live attendance to qualify. Duplicate or fraudulent entries will be disqualified automatically.