One Week Left to get an iPad, ASUS Chromebook or Take $250 Off with Online Training!


To attend this webcast, login to your SANS Account or create your Account.

High Fidelity Alerts: How to create custom alerts like a pro

  • Wednesday, May 30th, 2018 at 10:30 AM EDT (14:30:00 UTC)
  • Justin Henderson and John Hubbard
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!


Creating a high fidelity alert requires knowing how alert engines function and what their capabilities are. Let's face it, many built-in alerts need tuned or disabled due to lack of context or a massive amount of false positives generated. This webcast focuses on how alert engines operate, what rule types are available, and how to create alerts that are high fidelity and easy to implement.

Speaker Bios

Justin Henderson

Justin is a passionate security architect and researcher with over decade of experience working in the Healthcare industry as well as consulting. He has had multiple opportunities to work on government contracts specializing in network monitoring systems and intrusion analysis. Justin was the 13th GSE to become both a red and blue SANS Cyber Guardian and holds over around 60 industry certifications.

Justin is a SANS instructor and the author of SEC555, the industry's first vendor neutral SIEM analytics course.

John Hubbard

John is currently the Lead Analyst for GlaxoSmithKline's U.S. Security Operations Center. His daily responsibilities include detecting and defending against targeted attacks, threat hunting, incident response, and malware reverse-engineering. With degrees in Electrical and Computer Engineering focusing on Cyber Security, his interest and research spans from malware, penetration testing, and security monitoring, to mobile device attacks, car hacking, and IoT. He is GIAC GMON, GPEN, and GREM certified, is passionate about information security, loves learning, and is enthusiastic about helping others succeed in their studies.

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.