flâneur — a map of the web's best reading

A SOCless Detection Team at Netflix | LinkedIn

linkedin.com · 1,291 words · saved by 1 readers

I am excited to share that we are investing in additional detection capabilities as part of the SIRT mission. There are a number of existing detection efforts across Netflix security teams. This is an opportunity to further those efforts, while creating stronger alignment between detection and response. Of course this being Netflix, our culture and our tech stack loom large in our consideration of how to expand our detection program. We want to avoid traditional pitfalls and optimize for our novel security approach. The last thing we want is a bunch of lame alerts creating busy work for a large standing SOC. Required reading for anyone interested in this area are Ryan McGeehan’s Lessons Learned in Detection Engineering and the Alerting and Detection Strategy work from Palantir. I have borrowed liberally from their efforts. There are many ways to break this down, but I have settled on the following: Within these categories, this is what a mature program looks like, and some questions we

I am excited to share that we are investing in additional detection capabilities as part of the SIRT mission. There are a number of existing detection efforts across Netflix security teams. This is an opportunity to further those efforts, while creating stronger alignment between detection and response. Of course this being Netflix, our culture and our tech stack loom large in our consideration of how to expand our detection program. We want to avoid traditional pitfalls and optimize for our novel security approach. The last thing we want is a bunch of lame alerts creating busy work for a larg

Explore this link on the map →

related reading