Table stakes for Detection Engineering
This is a blog post I imported from another platform. I got some great feedback from it and thought it’d be good to share it here and keep things in one spot! Dracula refuses a call with a security vendor For as long as I have been in the security industry, there has been a concerted effort to sort through massive troves of data with powerful and mysterious tools called “rules”. It allows us mere mortals to take a million-line logfile and separate each line into two buckets: interesting or not interesting, malicious or not malicious, and vulnerable or not vulnerable. If you know what “bad” or “vulnerable” is, then you can codify it and let the computer do the sorting for you. I cut my teeth in security research, writing WAF rules for modsecurity and looking for interesting HTTP-based attacks on behalf of a customer base. I also launched the security detection and research team at startups that are now public. At my current gig, I help my organization write detection content against 100
Table stakes for Detection Engineering Import of a blog I wrote in October Zack Allen Dec 12, 2022 10 Share This is a blog post I imported from another platform. I got some great feedback from it and thought it’d be good to share it here and keep things in one spot! What is a rule, really? Dracula refuses a call with a security vendor For as long as I have been in the security industry, there has been a concerted effort to sort through massive troves of data with powerful and mysterious tools called “rules”. It allows us mere mortals to take a million-line logfile and separate each line into t
Explore this link on the map →related reading
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- detection-engineering-maturity-matrixdetectionengineering.io
- Mediumcyb3rops.medium.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- More on Threat Huntingtaosecurity.blogspot.com
- A SOCless Detection Team at Netflixlinkedin.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Why Detection Rules Fail: Causes, Effects, and Corrective Actionspicussecurity.com