flâneur — a map of the web's best reading

Lessons Learned in Detection Engineering | by Ryan McGeehan | Starting Up Security | Medium

medium.com · saved by 1 readers

Every security program eventually gains the ability to “detect” bad things happening on their systems. This creates the burden of manual analysis and escalation, and it’s hard to do well. More recently in my career, I’ve abandoned the desire to run a security team in favor for exploring how security teams run. This has given me wonderful exposure to varying qualities of intrusion detection approaches, both good and bad, and these are the notes I’ve put together on what qualities describe high functioning detection teams. Some of what follows will describe the trajectory of several roadmaps and where security teams hope to be. We’ll be talking through detection infrastructure that is dependent on logs with rules that trigger automation, prepares leads for hunts, or raises alerts. Great teams are not solving detection problems with analysts. When a human being is needed to manually receive an alert, contextualize it, investigate it, and mitigate it… it is a declaration of failure. Newer

Every security program eventually gains the ability to “detect” bad things happening on their systems. This creates the burden of manual analysis and escalation, and it’s hard to do well. More recently in my career, I’ve abandoned the desire to run a security team in favor for exploring how security teams run. This has given me wonderful exposure to varying qualities of intrusion detection approaches, both good and bad, and these are the notes I’ve put together on what qualities describe high functioning detection teams. Some of what follows will describe the trajectory of several roadmaps and

Explore this link on the map →