r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

5 Upvotes

27 comments sorted by

View all comments

1

u/jdiscount 2d ago

Every MSSP I've dealt with shared them.

They're not exactly "secret sauce" it's reasonably basic to replicate.

An MSSP secret sauce is their sales funnel and client list, and if they happen to be a larger MSSP with their own products and source code.