Creating data-driven detections with DataDog and JupyterHub
ID: c5e43c03-aa4d-5bfa-93ad-ba77a507b204
STIX ID: report--c5e43c03-aa4d-5bfa-93ad-ba77a507b204
Feed Name: Expel Blog
This article explains Expel's approach to reducing noisy brute-force and password-spraying alerts by instrumenting threshold-based detections with DataDog metrics, using Jupyter Notebooks to visualize and simulate threshold changes, automating review recommendations, and correlating additional signals (e.g., successful logins, account lockouts, GreyNoise enrichment) and seasonal anomaly detection to improve true positive rates and SOC analyst effectiveness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
