flâneur — a map of the web's best reading

Detection Coverage and Detection-in-Depth | by Anton Chuvakin | Anton on Security | Medium

medium.com · saved by 1 readers

For some time, I’ve been also fascinated with the concept of detection-in- depth and a somewhat related concept of optimal detection coverage. This fascination was born out of a particular type of analyst inquiry I used to get: if I have SIEM, do I also need an EDR? If I have SIEM with sysmon and Zeek data, do I also need an NTA tool? If I have anti-malware tool with an EDR module and a separate NTA tool, do I also need a SIEM? These all map to a problem of detection layers and detection coverage, hence “detection in depth.” While many people ramble about “defense in depth, ” I feel that much fewer actually implement and practice layers of detection controls in their environments. As often happens in security, talkers talk … while some doers don’t do — they just buy more tools and then have them sit unused :-) You can also look at this as a logical evolution of defense in depth. The whole premise was that you were preventing things with layers of controls. Now, the premise is you shoul

For some time, I’ve been also fascinated with the concept of detection-in- depth and a somewhat related concept of optimal detection coverage. This fascination was born out of a particular type of analyst inquiry I used to get: if I have SIEM, do I also need an EDR? If I have SIEM with sysmon and Zeek data, do I also need an NTA tool? If I have anti-malware tool with an EDR module and a separate NTA tool, do I also need a SIEM? These all map to a problem of detection layers and detection coverage, hence “detection in depth.” While many people ramble about “defense in depth, ” I feel that much

Explore this link on the map →