Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYI
It's not hard to guess that just a few enterprise organizations today have the luxury of having both #ThreatHunting and #DetectionEngineering practices as part of their services portfolio. After all, consider it's challenging to enable and find practitioners. While many organizations have 'Detection & Response' as a single team, there are other setups with one team responsible for both Hunting and Detection, which is perhaps an easier or obvious choice. Now, can you imagine how inefficient that can turn out to be in case an organization doesn't realize how super-connected those practices are? I need to start here as that makes it easier to understand, not only for the wider audience, but for us, hunters and detection engineers. Besides data in the form of log telemetry or any other digital artifact, what is missing before engaging on a hunt or a detection idea? Can you imagine hunting or detecting — without Cyber Threat Intelligence input? Earlier this year I did explore this topic in
Navigating the crossroads of Threat Hunting & Detection Engineering Alex Teixeira 5 min read · Oct 31, 2023 -- Listen Share It's not hard to guess that just a few enterprise organizations today have the luxury of having both #ThreatHunting and #DetectionEngineering practices as part of their services portfolio. After all, consider it's challenging to enable and find practitioners. While many organizations have 'Detection & Response' as a single team, there are other setups with one team responsible for both Hunting and Detection, which is perhaps an easier or obvious choice. Now, can you imagi
Explore this link on the map →saved by
related reading
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- More on Threat Huntingtaosecurity.blogspot.com
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com