all InfoSec news
Telemetry Layering
Security Boulevard securityboulevard.com
Introduction
Creating detections can be challenging. There often isn’t a “simple” way to detect something, and once we see an event that seems to correlate with the activity we are looking for, it is easy to become fixated. We create that detection and move on. However, what if other telemetry sources had helped provide a different context to that action of interest? Could we have created multiple detections with various telemetry sources to provide better coverage? If a telemetry source …
action context detect detection detection engineering detections event interest introduction isn research simple telemetry