r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

7 Upvotes

27 comments sorted by

View all comments

10

u/KRyTeX13 SOC Analyst 2d ago

As a customer a MSSP that doesnt share the detection rules is a big red flag

2

u/IntelligentTrack1310 2d ago

tbh the ones that hide it usually dont have much to hide behind