WhatDR or What Detection Domain Needs Its Own Tools? | by Anton Chuvakin | Anton on Security | Medium
This is the blog where I really (briefly) miss my analyst life and my “awesome+” peers like Augusto and Anna. It relies on ideas and comments from my past collaborators … and my current ones. And, yes, this blog was inspired by a hallways conversation at a conference that took place more than a year ago :-( So, the question: Bear with me for a moment as we ponder this mystery. Everybody knows EDR, some know NDR, a few ramble about XDR. We also have ITDR emerging (IMHO, ITDR is a bastard half-brother of UEBA). We talk of CDR for cloud. Some vendors tried to create DDR (for data). I almost forgot MDR (Gemini helpfully reminded me), but this is different (because service aka “rent a human”). There was once a clown who tried making VMDR (OMG, this is the dumbest, as it makes no sense whatsoever). ADR for Application Detection and Response is probably coming, because ASPM is here already (this eBPF observability stuff may yet lead to more odd-duck *DRs or RASP 2.0… but I digress). And, gods
5 min read Mar 7, 2024 -- Press enter or click to view image in full size Pondering ?DR This is the blog where I really (briefly) miss my analyst life and my “awesome+” peers like Augusto and Anna. It relies on ideas and comments from my past collaborators … and my current ones. And, yes, this blog was inspired by a hallways conversation at a conference that took place more than a year ago :-( So, the question: When and where do you need “<domain>DR” tool for its own technology domain? Bear with me for a moment as we ponder this mystery. Everybody knows EDR, some know NDR, a few…
related reading
- Empowering Threat Detection With Custom Detections in EDRtruesec.com
- Anton and The Great XDR Debate, Part 1medium.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Boxer: Data Analytics on Network-enabled Serverless Platformsresearch-collection.ethz.ch
- What Is Identity Threat Detection & Response (ITDR)? | Proofpoint USproofpoint.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- EDR Internals for macOS and Linuxoutflank.nl
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- What is Cloud Detection and Response (CDR)? | Wizwiz.io
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Report: The Era of Endpoints | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com