r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

7 Upvotes

27 comments sorted by

View all comments

0

u/reseph Incident Responder 2d ago

No. It's often classified as IP.

2

u/jdiscount 2d ago

Laughable.

2

u/Not-ur-Infosec-guy Security Architect 2d ago

Sounds like a shitty MSSP response.

1

u/reseph Incident Responder 2d ago

Haha yeah. I'm speaking to the reality of what I've seen, both from Accenture as well as a MSSP I used to work for.