Detection Engineering the SOC: Writing a Detection Rule | by RCXSecurity | Medium
Welcome to the first article of a new three part mini-series at the Cybersec Cafe called “Detection Engineering in the SOC” — covering a real life use case for Detection Engineering. As a refresher, the SOC stands for the Security Operations Center, which is the departmenet within an organization responsible for monitoring, detecting, responding to, and mitigating security threats and incidents. In this mini-series, I’ll be taking a detection end-to-end through the detection lifecycle (DLC) and giving an inside look at the thought process of Security Engineers and how they build out the SOC. In this series, we’ll be covering the following topics, so make sure to save the post and subscribe as I’ll post them over the coming weeks. Or, if you want to get ahead, you can also find the series already publishes on my blog, the Cybersec Cafe. In the first article of this series, we’ll start with writing a Detection Rule. In essence, a Detection Rule defines patterns, behaviors, or indicators
Welcome to the first article of a new three part mini-series at the Cybersec Cafe called “Detection Engineering in the SOC” — covering a real life use case for Detection Engineering. As a refresher, the SOC stands for the Security Operations Center, which is the departmenet within an organization responsible for monitoring, detecting, responding to, and mitigating security threats and incidents. In this mini-series, I’ll be taking a detection end-to-end through the detection lifecycle (DLC) and giving an inside look at the thought process of Security Engineers and how they build out the SOC. I
Explore this link on the map →