flâneur — a map of the web's best reading

How to prioritize a Detection Backlog? | by Alex Teixeira | May, 2024 | Detect FYI

detect.fyi · 1,105 words · saved by 1 readers

I started writing Medium stories in 2017 and the very first article was "How to rank Quick Wins", a fascinating topic that deserved another take. That initial take was mainly about good problems to have as detection engineer, from rich log data, to a backlog full of great ideas to implement. Today, the good problem is not that different. It's just bigger! A few years ago, security monitoring teams faced many challenges in properly instrumenting the right log telemetry. Often, Windows Eventlogs, as an example, were only enabled on Domain Controllers! Persuading administrators to deploy new agents was a daunting task. Today, this scenario has evolved significantly due to the increased adoption of EDR agents and advanced security instrumentation techniques. What about Data Engineering? The added value is tremendous. That includes the selective ingestion of log data, the ability to enrich logs before they reach the SIEM and the overall simplification of log management processes. Now, with

Detection Engineering Security Analytics Siem Soc Threat Intelligence How to prioritize a Detection Backlog? Alex Teixeira 5 min read · May 13, 2024 -- 7 Listen Share I started writing Medium stories in 2017 and the very first article was " How to rank Quick Wins ", a fascinating topic that deserved another take. That initial take was mainly about good problems to have as detection engineer, from rich log data, to a backlog full of great ideas to implement. Today, the good problem is not that different. It's just bigger! Abundant Log Telemetry A few years ago, security monitoring teams faced m

Explore this link on the map →

related reading