Summary
In this chapter, we first looked at the phases involved in creating and documenting detection requirements. We defined a methodology for scoring and prioritizing requirements allowing an organization to triage requests from multiple stakeholders. Lastly, we worked through some example scenarios using this prioritization approach to demonstrate how it can be used to support a detection engineering team.
In the next chapter, we’re going to work through multiple example detections to demonstrate the design and creation process of detection rules for various scenarios. Then we’ll briefly touch on testing our new detections.