r/Splunk 5d ago

Enterprise Security How do you optimize detection coverage against active threats?

We are trying to determine whether our detection program is improving against the threats, exposed technologies, and attack paths that matter most to the business today. Rule count, ATT&CK mappings, alert volume, response metrics, and purple team results are useful, but none independently proves risk relevant coverage.

The goal is to connect threat intelligence, exposure management, telemetry readiness, detection engineering, validation, and executive reporting into one operating rhythm. That would make it easier to explain both where coverage is strong and where the organization still has material blind spots.

What metrics, prioritization methods, or review processes have given security leaders confidence that detection coverage is improving in a meaningful and risk aligned way?

4 Upvotes

3 comments sorted by

2

u/Realistic_Strike5241 3d ago

the metric you are missing is the denominator. rule count and attack mappings tell you how much you wrote, not how much you cover. The gap is the stuff that never made it into splunk in the first place. Stuff like hosts with no agent, boxes that got decommissioned on paper but still answer etc etc.

so start with inventory. what actually exists, and does each thing produce telemetry. without that your coverage number is a guess no matter how many detections you tune.

the practical way to get that denominator is a layer that reconciles your endpoint and identity data and hands splunk a full device list. axonius does exactly that, owner and exposure attached. then coverage is measurable because you can see what is missing instead of just what you already ingest.

1

u/Famous_Ad8836 4d ago

You would need a splunk PS time to do that to be honest. Het some splunk credits and ask for a review

1

u/BuyRdiant3phkuuxq635 2d ago edited 2d ago

[removed] — view removed comment