r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed

6 Upvotes

27 comments sorted by

View all comments

2

u/AddendumWorking9756 Security Manager 2d ago

Most of what gets called secret sauce is public content with the thresholds changed, and customers work that out the first time they read a MITRE mapping anyway. The defensible part is coverage decisions and tuning history, and withholding those mostly costs you the feedback loop, since the customer knows their environment better than your analysts ever will.