The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering | by Alex Teixeira | Detect FYI
This is just another quick blog that could not fit in a tweet which is hopefully inspiring for for all Detection Engineering teams out there. First off, let's get the definitions loud and clear: Novelty: the quality of being new, original, or unusual. Behaviour: the way in which one acts or conducts oneself. Those are perhaps the main traits we should consider when designing or engineering a detection system. I used to say Forensics happens after the fact while Detection should happen right after the fact and both are really challenging! Let alone Prevention which should happen before the fact! But that's a story for another post… Just like in Forensics, the Locard’s principle applies here: Every contact leaves a trace. Attackers will both bring something with them and will leave with something from the system. Our challenge is to find out which artifacts tie to that principle. That brings us to the next point. The answer is pretty simple. The same as in Computer Forensics: the crime s
The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering Alex Teixeira 3 min read · Aug 10, 2021 -- Listen Share This is just another quick blog that could not fit in a tweet which is hopefully inspiring for for all Detection Engineering teams out there. First off, let's get the definitions loud and clear: Novelty: the quality of being new, original, or unusual. Behaviour: the way in which one acts or conducts oneself. Those are perhaps the main traits we should consider when designing or engineering a detection system. One action, multiple traces I used to say Foren
Explore this link on the map →related reading
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Mediumdetect.fyi
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Mediumcyb3rops.medium.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- detection-engineering-maturity-matrixdetectionengineering.io
- A gentle introduction to mechanistic anomaly detection — LessWronglesswrong.com
- Table stakes for Detection Engineering - by Zack Allendetectionengineering.net