flâneur — a map of the web's best reading

The Threat Detection Balancing Act: Coverage vs Cost | by VanVleet | Medium

medium.com · saved by 1 readers

This article is part of a series on Threat Detection, if you haven’t read the earlier articles, you might want to do that first. As discussed in my article on strategy, threat detection is like a game of probability: we try to build preventative mechanisms and detections that cover enough of the attack surface that it’s unlikely an attacker will find a path through our network without triggering one of our alarms and alerting us to their presence. In this post, I’m going to explore some of the practical realities and constraints involved in maximizing our attack surface coverage and the implications for threat detection efforts. At first blush, the best approach seems to be to deploy as many detections as possible, maximizing our coverage through overwhelming numbers. This approach is facilitated by the many available collections of public or commercially-provided detection content. For example, Elastic Security advertises 800 SIEM rules plus 380 endpoint rules in their version 8.8 rel

This article is part of a series on Threat Detection, if you haven’t read the earlier articles, you might want to do that first. As discussed in my article on strategy, threat detection is like a game of probability: we try to build preventative mechanisms and detections that cover enough of the attack surface that it’s unlikely an attacker will find a path through our network without triggering one of our alarms and alerting us to their presence. In this post, I’m going to explore some of the practical realities and constraints involved in maximizing our attack surface coverage and the implic

Explore this link on the map →