The Detection Engineering Process
ID: c399915f-db7e-5f50-87f6-cc759f5338f8
STIX ID: report--c399915f-db7e-5f50-87f6-cc759f5338f8
Feed Name: Black Hills Infosec Blog
This webcast transcript explains a detection engineering workflow that applies the scientific method to create high-quality security detections: start with a clear detection story, perform focused research, build and tune queries, backtest historical data, deploy canaries to validate ongoing operation, document using the ADS framework, onboard with suppression/throttling and a burn-in period, and continuously improve while managing risk; a PSExec plaintext-password detection is used as a concrete example, and the talk also covers practical topics like query language nuances, use of AI to assist documentation, and trade-offs in suppression and risk-based alerting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
