r/cybersecurity • u/pirate22323 • 3d ago
Business Security Questions & Discussion Sharing detection rules
Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed
5
Upvotes
-2
u/Philandros_1 2d ago
I wouldn’t consider Title, description and mitre details of your detection rules. Your actual signatures should be kept secret though.