Threat detection metrics: exploring the true-positive spectrum | by Alex Teixeira | Medium
I’ve had the chance to work with many great security teams during my career and in 2012, I had the opportunity to join Verizon's SOC in Germany. That was a very challenging experience considering its massive scale SecOps. It was also by that time when I realized Splunk could be used as a sort of BI/Reporting platform given its ability to quickly generate eye-catching reports or dashboards from case or incident management systems data. Today, when designing and building detection mechanisms, it's easier to notice the link between threat detection engineering practice and overall SOC services quality, regardless of target customer (internal/external). Without going too deep on that, I guess the true-positive (TP) versus false-positive (FP) classification became widespread in Infosec after the introduction of pattern based Network Intrusion Detection Systems (NIDS). In a nutshell, here's how the assessment is done: "Does the input (network flow) match a pattern?" If yes, it must be either
Threat detection metrics: exploring the true-positive spectrum Alex Teixeira 6 min read · Jun 12, 2019 -- 1 Listen Share I’ve had the chance to work with many great security teams during my career and in 2012, I had the opportunity to join Verizon's SOC in Germany. That was a very challenging experience considering its massive scale SecOps. It was also by that time when I realized Splunk could be used as a sort of BI/Reporting platform given its ability to quickly generate eye-catching reports or dashboards from case or incident management systems data. Today, when designing and building detec
Explore this link on the map →related reading
- Identifying & Reducing False Positive Alertspanther.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- detection-engineering-maturity-matrixdetectionengineering.io
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- Intrusion Detection | Computer Securitytextbook.cs161.org