Building the Threat Detection Ecosystem at Brex | by Julie Agnes Sparks | Brex Tech Blog | Medium
The Detection & Response Team at Brex recently open sourced Substation, our toolkit for achieving high-quality data through interconnected, serverless data pipelines. However, Substation is just one part of our threat detection ecosystem, this blog post describes our approach to building a threat detection platform in a vendor-agnostic way that aligns with our overall detection vision. At Brex, we see the Threat Detection Platform as all systems that contribute to the ability to create and execute detections in our environment — from ingesting and enriching logs using Substation to a centralized querying environment to processes that execute detections and optionally trigger interactions in an alerting system and a SOAR solution. The ability to detect threats in our environment is constrained by the availability and quality of data, and the success of each detection relies on the execution of enrichment, intelligence data, and optional automation in a timely manner. We build modular, e
The Detection & Response Team at Brex recently open sourced Substation, our toolkit for achieving high-quality data through interconnected, serverless data pipelines. However, Substation is just one part of our threat detection ecosystem, this blog post describes our approach to building a threat detection platform in a vendor-agnostic way that aligns with our overall detection vision. At Brex, we see the Threat Detection Platform as all systems that contribute to the ability to create and execute detections in our environment — from ingesting and enriching logs using Substation to a centraliz
Explore this link on the map →