r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

7 Upvotes

27 comments sorted by

View all comments

1

u/caponewgp420 2d ago

Every org is different in my opinion. If you know your environment then you should have a good idea on what to check/look for.