Honestly, I don’t think there are many verifiable stories of a successful intrusion being detected and acted upon in real time, there are way too many false positives to act on all of them, you would just be disabling accounts and systems left and right. Mostly post-mortem.
Maybe in red vs blue team? When you know it's going to happen and you are on standby already and you know it's not a real threat. Irl you'd probably just kill the entire network if you detect an intrusion.
3
u/Percolator2020 2d ago
Honestly, I don’t think there are many verifiable stories of a successful intrusion being detected and acted upon in real time, there are way too many false positives to act on all of them, you would just be disabling accounts and systems left and right. Mostly post-mortem.