flâneur — a map of the web's best reading

Table stakes for Detection Engineering

detectionengineering.net · 1,575 words · saved by 1 readers

This is a blog post I imported from another platform. I got some great feedback from it and thought it’d be good to share it here and keep things in one spot! Dracula refuses a call with a security vendor For as long as I have been in the security industry, there has been a concerted effort to sort through massive troves of data with powerful and mysterious tools called “rules”. It allows us mere mortals to take a million-line logfile and separate each line into two buckets: interesting or not interesting, malicious or not malicious, and vulnerable or not vulnerable. If you know what “bad” or “vulnerable” is, then you can codify it and let the computer do the sorting for you. I cut my teeth in security research, writing WAF rules for modsecurity and looking for interesting HTTP-based attacks on behalf of a customer base. I also launched the security detection and research team at startups that are now public. At my current gig, I help my organization write detection content against 100

Table stakes for Detection Engineering Import of a blog I wrote in October Zack Allen Dec 12, 2022 10 Share This is a blog post I imported from another platform. I got some great feedback from it and thought it’d be good to share it here and keep things in one spot! What is a rule, really? Dracula refuses a call with a security vendor For as long as I have been in the security industry, there has been a concerted effort to sort through massive troves of data with powerful and mysterious tools called “rules”. It allows us mere mortals to take a million-line logfile and separate each line into t

Explore this link on the map →

related reading