Threat assessments
As mentioned in the Threat intelligence in the detection engineering life cycle section of this chapter, threat assessments are a source of valuable detection requirements. Threat assessments define a process for evaluating threats to an organization and its information systems and describing those threats, providing a report detailing organization-specific risks. Organizations often leverage threat assessments to identify areas for improvement of detection and prevention coverage. Sometimes, this can be the identification of vulnerabilities or misconfigurations that should be changed to prevent certain threats. It can also include information about the types of threats and attack vectors that are the greatest risk to your organization. This is where most of the value, for detection engineers, comes from, as the identification of these risks allows us to determine what coverage is most applicable to our organization.
Since performing threat assessments and details...