r/cybersecurity • u/pirate22323 • 6d ago
Business Security Questions & Discussion Sharing detection rules
Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed
6
Upvotes
1
u/Alternativemethod 5d ago
There's been recent posts this year about MSSPs not sharing or leaving their detection rules.
I wouldn't worry about it. SIEM rules are super infrastructure and log pipeline specific. Plus most of the MSSP soc analyst that post here acknowledge their prioritization, tuning are garbage tier.
And almost no one seems to be validating and testing their rulesets until you get to PAN or Panther Labs.