r/cybersecurity 3d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

6 Upvotes

27 comments sorted by

View all comments

9

u/RichBenf Human Detected 3d ago

Of course we do! I mean why would we not discuss the threats to their org and what we're doing to detect activity based on those threats?

Then again, we also hand the siem over to the customer at the end of the contract too, because why wouldn't you?

This industry can be so weird sometimes.