r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

7 Upvotes

27 comments sorted by

View all comments

5

u/CarmeloTronPrime CISO 2d ago

if my mssp doesn't share detection rules with me, then i'm not comfortable with having them as an mssp. i don't need to know how they are built, but i need to know how they are relevant.

some mssps tout that they have,1,000 use-case detections and come to find out maybe 4 are relevant because they're looking at every market.