flâneur — a map of the web's best reading

The Shift-Left strategy applied to Threat Detection | by Alex Teixeira | Detect FYI

detect.fyi · 1,410 words · saved by 1 readers

This is a quick one just to share a win I've been recently through that might be applicable or inspirational (why not?) to some while sharing my unasked opinion on SOAR — from a detection engineer perspective. Before exploring the topic deeper, check if you agree on the following needs: Now, how many of those problems are solved with SOAR? It depends on the product? It depends on who implement or runs the product (skillset)? It depends on many factors, not arguing SOAR cannot help here. It's hard to say but I've seen quite a few, including Swimlane, SIEMplify and other enterprise-grade options. There are two observations I can share: Oh the playbooks… If you are into SIEM and not following the work from Anton Chuvakin, you are probably not into SIEM for long. He's a true SIEM (or SIM?) wizard with many, many interesting views on the topic that have been inspiring a lot of blueteamers in our community. BTW, this technology has turned 20 years! It's pretty common for many thought leaders

The Shift-Left strategy applied to Threat Detection Alex Teixeira 6 min read · Mar 30, 2022 -- 1 Listen Share This is a quick one just to share a win I've been recently through that might be applicable or inspirational (why not?) to some while sharing my unasked opinion on SOAR — from a detection engineer perspective. Press enter or click to view image in full size Before exploring the topic deeper, check if you agree on the following needs: We all need a proper, investigation driven case/ticket/incident management system. Extra points if it makes collaboration easier! We all need to provide r

Explore this link on the map →

related reading