Detection Spectrum. Have you ever heard someone call… | by Jared Atkinson | Posts By SpecterOps Team Members
The Funnel of Fidelity is a model that SpecterOps uses to describe the phases involved in the detection and response process. We like to associate each blog post with the phase(s) that the post’s topics relate to. This specific post is focused on a strategy that can be applied to the Detection phase of the funnel. Detection Engineering with Kerberoasting Blog Series: This is the second of a multipart detection engineering blog series by the SpecterOps detection team. The goal of this series is to introduce and discuss foundational detection engineering concepts. To make these concepts as consumable as possible, we are focusing the entire series around Kerberoasting. Focusing on this technique allows readers to focus on the strategies presented in each article instead of worrying about the details of the technique itself. The first post of the series discussed the concept of capability abstraction which is how tools abstract the complexities of the attack techniques they enable. Below i
Back to Blog Research & Tradecraft Detection Spectrum Author Jared Atkinson Read Time 11 mins Published Feb 21, 2020 Share Put Insights Into Action Explore our Platform Explore Services [ RS - Classic Editor Block ] The Funnel of Fidelity is a model that SpecterOps uses to describe the phases involved in the detection and response process. We like to associate each blog post with the phase(s) that the post’s topics relate to. This specific post is focused on a strategy that can be applied to the Detection phase of the funnel. Detection Engineering with Kerberoasting Blog Series: Post 1: Capabi
Explore this link on the map →related reading
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Capability Abstraction - SpecterOpsposts.specterops.io
- Intrusion Detection | Computer Securitytextbook.cs161.org
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Identifying & Reducing False Positive Alertspanther.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Bad Idea: Deterrence by Detection | Defense360defense360.csis.org
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- detection-engineering-maturity-matrixdetectionengineering.io
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- More on Threat Huntingtaosecurity.blogspot.com