Detection Engineering the SOC: Designing an Incident Response Playbook | by RCXSecurity | Medium
Welcome back to the second article in the mini-series, Detection Engineering the SOC! In Part II, we’ll be deep diving into the mind of a Security Engineer taking a detection through the Detection Lifecycle (DLC). This time, specifically through the creation of an Incident Response playbook. If you want to jump around in the series, you can view the table of contents below. Make sure to save the post and subscribe as I’ll post the final part in the coming weeks. Or, if you want to get ahead, you can also find the series already publishes on my blog, the Cybersec Cafe. Looking for daily cybersecurity content? Check me out on Twitter/X! But, just in case you missed Part I, let me give you a quick recap: We had a use case for a fictional company that needed an Alert to trigger whenever a login was made to their AWS instance without using Multi-Factor Authentication (MFA). This was because there were some highly-privileged developers that needed to access the console outside of MFA to acce
Welcome back to the second article in the mini-series, Detection Engineering the SOC! In Part II, we’ll be deep diving into the mind of a Security Engineer taking a detection through the Detection Lifecycle (DLC). This time, specifically through the creation of an Incident Response playbook. If you want to jump around in the series, you can view the table of contents below. Make sure to save the post and subscribe as I’ll post the final part in the coming weeks. Or, if you want to get ahead, you can also find the series already publishes on my blog, the Cybersec Cafe. Looking for daily cyberse
Explore this link on the map →