SigmaHQ Essentials - Building Robust Detection Capabilities

Intro

We advocate and discuss SigmaHQ repository of detections frequently on Thursday Defensive, but we never go into too much detail. There are always lingering questions of what type of detections do we use? How do you tune those rules? What other tools use these rules? So as one of the detection engineers at Recon, I figured I would share some of the knowledge I’ve obtained over the last 6 years of dealing with SigmaHQ detections in my day-to-day operations.

原始链接: https://blog.reconinfosec.com/sigmahq-essentials-building-robust-detection-capabilities
侵权请联系站方: [email protected]

相关推荐

换一批