A SOCless Detection Team at Netflix | LinkedIn
I am excited to share that we are investing in additional detection capabilities as part of the SIRT mission. There are a number of existing detection efforts across Netflix security teams. This is an opportunity to further those efforts, while creating stronger alignment between detection and response. Of course this being Netflix, our culture and our tech stack loom large in our consideration of how to expand our detection program. We want to avoid traditional pitfalls and optimize for our novel security approach. The last thing we want is a bunch of lame alerts creating busy work for a large standing SOC. Required reading for anyone interested in this area are Ryan McGeehan’s Lessons Learned in Detection Engineering and the Alerting and Detection Strategy work from Palantir. I have borrowed liberally from their efforts. There are many ways to break this down, but I have settled on the following: Within these categories, this is what a mature program looks like, and some questions we
I am excited to share that we are investing in additional detection capabilities as part of the SIRT mission. There are a number of existing detection efforts across Netflix security teams. This is an opportunity to further those efforts, while creating stronger alignment between detection and response. Of course this being Netflix, our culture and our tech stack loom large in our consideration of how to expand our detection program. We want to avoid traditional pitfalls and optimize for our novel security approach. The last thing we want is a bunch of lame alerts creating busy work for a larg
Explore this link on the map →related reading
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Rebuilding Threat Detection and Incident Response at LinkedInlinkedin.com
- detection-engineering-maturity-matrixdetectionengineering.io
- Table stakes for Detection Engineering - by Zack Allendetectionengineering.net
- Mediumblog.palantir.com
- Creating Cost-Effective, Scalable Detectionsrippling.com