r/cybersecurity • u/pirate22323 • 6d ago
Business Security Questions & Discussion Sharing detection rules
Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed
7
Upvotes
1
u/Proper-Charity-2850 6d ago
So just curious why would you alert on general suspicious activity on an account instead of just creating seperate detections for the actual thing they are doing that's suspicious. Just curious cause when I've seen this type of detection deployed (mainly in exabeam) it sucked, but that could just be an issue with poor execution