SOC Bare Minimum: Getting Out of the Matrix
How could we miss an inbound SSH connection from an external IP? The “T1133: External Remote Services” cell in our MITRE matrix was green. Of course it was. We had a rule for RDP, another two for our VPN, even one for some fancy Docker abuse. But not for SSH. Crazy, right? And yet this is how most SOCs measure their detection gaps. ATT&CK is good at showing and organizing what you cover, but it won’t tell you how well you cover it, and it definitely won’t tell you if you’re missing the basics. ...
Before you automate the SOC: building playbooks for alerts you haven't seen yet
Writing reliable playbooks to guide the analysts who investigate alerts has always mattered. But when that investigation is automated with AI, it matters more than ever. A human analyst quietly compensates for the playbook’s deficiencies, and even points them out so they can be fixed. They also get it wrong sometimes, of course, but the damage is local: just one or a few misclassified alerts. If that bad instruction is given to an automation, the error will propagate to every single alert, with nobody there to raise a hand about it. ...