Rebuilding Threat Detection and Incident Response at LinkedIn
LinkedIn connects and empowers more than 875 million members and over the past few years, has undergone tremendous growth. As an integral part of the Information Security organization at LinkedIn, the Threat Detection and Incident Response team (aka SEEK) defends LinkedIn against computer security threats. As we continue to experience a rapid growth trajectory, the SEEK team decided to reimagine its capabilities and the scale of its monitoring and response solutions. What SEEK set out to do was akin to shooting for the moon, so we named the program “Moonbase.” Moonbase set the stage for significantly more mature capabilities that ultimately led to some impressive results. With Moonbase, we were able to reduce incident investigation times by 50%, increase threat detection coverage expansion by 900%, and reduce our time to detect and contain security incidents from weeks or days to hours. In this blog, we will discuss how LinkedIn rebuilt its security operations platform and teams, scale
Rebuilding Threat Detection and Incident Response at LinkedIn Skip to main content LinkedIn respects your privacy LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including professional and job ads ) on and off LinkedIn. Learn more in our Cookie Policy . Select Accept to consent or Reject to decline non-essential cookies for this use. You can update your choices at any time in your settings . Accept Reject Security (Re)building Threat Detection and Incident Response at LinkedIn November 9, 2022
Explore this link on the map →related reading
- Automated Incident Response: Streamlining Your SecOps | Prophet Securityprophet.security
- A SOCless Detection Team at Netflixlinkedin.com
- Security incident disclosure — July 2026huggingface.co
- Customer Stories & Case Studies | Pantherpanther.com
- Creating Cost-Effective, Scalable Detectionsrippling.com
- Protect your organization as SIEM vendor, technology and threat landscape changeslinkedin.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- More on Threat Huntingtaosecurity.blogspot.com
- SurveyMonkey x Anvilogicanvilogic.com