flâneur — a map of the web's best reading

Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYI

detect.fyi · 1,001 words · saved by 1 readers

It's not hard to guess that just a few enterprise organizations today have the luxury of having both #ThreatHunting and #DetectionEngineering practices as part of their services portfolio. After all, consider it's challenging to enable and find practitioners. While many organizations have 'Detection & Response' as a single team, there are other setups with one team responsible for both Hunting and Detection, which is perhaps an easier or obvious choice. Now, can you imagine how inefficient that can turn out to be in case an organization doesn't realize how super-connected those practices are? I need to start here as that makes it easier to understand, not only for the wider audience, but for us, hunters and detection engineers. Besides data in the form of log telemetry or any other digital artifact, what is missing before engaging on a hunt or a detection idea? Can you imagine hunting or detecting — without Cyber Threat Intelligence input? Earlier this year I did explore this topic in

Navigating the crossroads of Threat Hunting & Detection Engineering Alex Teixeira 5 min read · Oct 31, 2023 -- Listen Share It's not hard to guess that just a few enterprise organizations today have the luxury of having both #ThreatHunting and #DetectionEngineering practices as part of their services portfolio. After all, consider it's challenging to enable and find practitioners. While many organizations have 'Detection & Response' as a single team, there are other setups with one team responsible for both Hunting and Detection, which is perhaps an easier or obvious choice. Now, can you imagi

Explore this link on the map →

saved by

related reading