Alert fatigue and desensitization, high false-positives, confirmation bias...sound familiar? One-for-one alerting models come with a lengthy list of cons compared to pros. For National Grid’s CSIRT team, too many questions were left unanswered. It was time for a more in-depth analysis of their attack surface. Leveraging their Tanium instance and the ‘Tanium MITRE Rule,’ they were able to apply additional correlation logic that reduced false positives, increased alert abilities, and get the most out of the telemetry coming from Tanium. Watch this short presentation to learn more.