home.social

#detectioncoverage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #detectioncoverage, aggregated by home.social.

  1. @timb_machine One day when we read links like br0k3nlab.com/resources/axioms people will have read the #OpenTide white paper and realized how it changes the conversation about #detectioncoverage but this day was not today.

  2. Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.

    You can't and shouldn't use MITRE #ATT&CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.

    If you want to do any sort of data driven #detectioncoverage you need #OpenTide -> there's no way around it.

    levelup.gitconnected.com/why-t

    ATT&CK is still ♥️ 😍 tho.

    #SOC #blueteam #detectionEngineering