Dealing with Noisy Behavioral Analytics in Detection Engineering
Hutchison, S., 2023: Dealing with Noisy Behavioral Analytics in Detection Engineering. Carnegie Mellon University, Software Engineering Institute's Insights (blog), Accessed July 31, 2024, https://doi.org/10.58012/mvtb-xb29. APA Citation Hutchison, S. (2023, October 30). Dealing with Noisy Behavioral Analytics in Detection Engineering. Retrieved July 31, 2024, from https://doi.org/10.58012/mvtb-xb29. Chicago Citation Hutchison, Sean. "Dealing with Noisy Behavioral Analytics in Detection Engineering." Carnegie Mellon University, Software Engineering Institute's Insights (blog). Carnegie Mellon's Software Engineering Institute, October 30, 2023. https://doi.org/10.58012/mvtb-xb29. IEEE Citation S. Hutchison, "Dealing with Noisy Behavioral Analytics in Detection Engineering," Carnegie Mellon University, Software Engineering Institute's Insights (blog). Carnegie Mellon's Software Engineering Institute, 30-Oct-2023 [Online]. Available: https://doi.org/10.58012/mvtb-xb29. [Accessed: 31-Jul-2
Dealing with Noisy Behavioral Analytics in Detection Engineering Sean Hutchison October 30, 2023 PUBLISHED IN Situational Awareness CITE https://doi.org/10.58012/mvtb-xb29 Get Citation SHARE Detection engineers and threat hunters understand that targeting adversary behaviors is an essential part of an effective detection strategy (think Pyramid of Pain ). Yet, inherent in focusing analytics on adversary behaviors is that malicious behavior will often enough overlap with benign behavior in your environment, especially as adversaries try to blend in and increasingly live off the land . Imagine y
Explore this link on the map →related reading
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- GitHub - open-edge-platform/anomalib: An anomaly detection library comprising state-of-the-art algorithms and features such as experiment management, hyper-parameter optimization, and edge inference. · GitHubgithub.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi