May 29, 2023
What is good detection, defined at micro-level for a rule or a piece of detection content?
What is good detection, defined at macro-level for a program at a company?
How to reliably produce good detection content at scale?
What is a detection content lifecycle that reliably produces good detections at scale?
What is the purpose of a SIEM today?
Where do you stand on a classic debate on vendor-written vs customer-created detection content?