Detection Engineering Fundamentals: What makes a good alert? | by br4dy5 | Jun, 2024 | Medium
If you find yourself developing custom detections to fill detection gaps in your environment, you may ask yourself: what does a good alert look like? As a detection engineer, you must think about your customer: the SOC. Your efforts need to balance two things: The challenge is that these objectives tend to have an inverse relationship. A detection engineer can write detections all day long to detect every possible indication of malicious activity. The result, however, will be an unrealistic volume of events requiring more effort than available capacity. On the flip side, not sufficiently detecting your attack surface will increase the risk of false negatives and successful breaches. So, how do you balance this? This is easier said than done, but this is the core responsibility of a detection engineer. Failure to do this will crush SOC capacity, desensitize analysts, and lead to alert fatigue. How to do this will have to be a subject for another blog 👀. 2. Provide as many investigative
If you find yourself developing custom detections to fill detection gaps in your environment, you may ask yourself: what does a good alert look like? As a detection engineer, you must think about your customer: the SOC. Your efforts need to balance two things: The challenge is that these objectives tend to have an inverse relationship. A detection engineer can write detections all day long to detect every possible indication of malicious activity. The result, however, will be an unrealistic volume of events requiring more effort than available capacity. On the flip side, not sufficiently detec
Explore this link on the map →