The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYI
There's no way out, the practices of Detection Engineering and Threat Hunting are becoming utterly important within a Cyber Security Program. How to define boundaries and establish ownership of the processes involved? Where's the overlap? Read along for some insights from the field. I have been writing about Detection Engineering for some years but never had the need to formally define it as the name implies it all: it's about engineering (cyber threat) detections. Is someone considered a Detection Engineer only if writing detections for a SIEM? What about other event or log-based platforms (ex.: Spark)? What about Yara, EDR, NIDS, WAF? The concept applies to many technologies. What's common from all of the above? There's some sort of automated built-in process. There's a rule or an analytics engine running code (process) inspecting data streams (input) and generating events (output). We give the engine some instructions (logic) and it starts spiting out indicators, alerts, signals or
The dotted lines between Threat Hunting and Detection Engineering Alex Teixeira 5 min read · Feb 25, 2023 -- 2 Listen Share There's no way out, the practices of Detection Engineering and Threat Hunting are becoming utterly important within a Cyber Security Program. How to define boundaries and establish ownership of the processes involved? Where's the overlap? Read along for some insights from the field. Give me a hunt, I give you a detection I have been writing about Detection Engineering for some years but never had the need to formally define it as the name implies it all: it's about engine
Explore this link on the map →saved by
related reading
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- More on Threat Huntingtaosecurity.blogspot.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Mediumcyb3rops.medium.com