flâneur — a map of the web's best reading

The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYI

detect.fyi · 1,147 words · saved by 1 readers

There's no way out, the practices of Detection Engineering and Threat Hunting are becoming utterly important within a Cyber Security Program. How to define boundaries and establish ownership of the processes involved? Where's the overlap? Read along for some insights from the field. I have been writing about Detection Engineering for some years but never had the need to formally define it as the name implies it all: it's about engineering (cyber threat) detections. Is someone considered a Detection Engineer only if writing detections for a SIEM? What about other event or log-based platforms (ex.: Spark)? What about Yara, EDR, NIDS, WAF? The concept applies to many technologies. What's common from all of the above? There's some sort of automated built-in process. There's a rule or an analytics engine running code (process) inspecting data streams (input) and generating events (output). We give the engine some instructions (logic) and it starts spiting out indicators, alerts, signals or

The dotted lines between Threat Hunting and Detection Engineering Alex Teixeira 5 min read · Feb 25, 2023 -- 2 Listen Share There's no way out, the practices of Detection Engineering and Threat Hunting are becoming utterly important within a Cyber Security Program. How to define boundaries and establish ownership of the processes involved? Where's the overlap? Read along for some insights from the field. Give me a hunt, I give you a detection I have been writing about Detection Engineering for some years but never had the need to formally define it as the name implies it all: it's about engine

Explore this link on the map →

saved by

related reading