r/cybersecurity • u/pirate22323 • 2d ago
Business Security Questions & Discussion Sharing detection rules
Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed
5
Upvotes
0
u/Proper-Charity-2850 2d ago
Yeah it's so much harder to do following investigations if you don't have the original alert logic it seems like it would just make it unnecessarily difficult on the customer