I built selected detections and carried out hunting and hardening work while keeping the broader coverage review, ownership and validation work in the backlog. Purple-team validation remained a planned next step for assessing the resulting detections against the relevant attack behaviour.
Viewed
UK Water Utility
Carry implemented work into the validation lifecycle
From Red Team findings to SQL and SMB detections
Return to the full story ←