The Importance of Custom Detections - Truesec
Every day, Truesec works with thousands of alerts and incidents from various security technologies. In most of these cases, vendor detection rules function as expected. However, in some cases, the vendor’s detections are not enough. Most security technologies support the use of custom detections, which allows our SOC engineers to create their own alerts based on insights from our security operations center, incident response missions, and our threat intelligence research. This is useful in several different scenarios, either during emerging campaigns or to fill in detection gaps in the product’s baseline. Custom detections for EDRs can include but are not limited to network, process, file, and even some WinAPI calls, depending on the vendor. As an example of a case where custom detections played an important role in identifying and stopping emerging threats, at the beginning of this year Truesec investigated a Qbot phishing campaign using OneNote files attached to emails. Qbot is an in
Managed detection and response Every day, Truesec works with thousands of alerts and incidents from various security technologies. In most of these cases, vendor detection rules function as expected. However, in some cases, the vendor’s detections are not enough. Most security technologies support the use of custom detections, which allows our SOC engineers to create their own alerts based on insights from our security operations center, incident response missions, and our threat intelligence research. This is useful in several different scenarios, either during emerging campaigns or to…
saved by
related reading
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Building a Detection Engine Part 1 — What is a Detection Engine?medium.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com