I helped connect business impact and attacker behaviour to the data needed for a detection. Telemetry work included DNS source attribution and cloud/on-premises traffic context. The use case records what needs to be observed and which data, parsers and investigation context it depends on.
Viewed
UK Water Utility
Start with the threat and the available evidence
Give Sentinel detections a path from threat to testing
Return to the full story ←