Investigating Detection Requirements
In Chapter 4, we discussed the various data sources that may be leveraged for creating and implementing detections. We also provided guidance on understanding what data sources provide the most value to your organization. Lastly, a new data source was added to our Elastic Stack as part of a lab demonstrating the inclusion of additional data sources.
Now that we know how to get data flowing through our detection engineering lab, we can begin discussing the detections themselves. In this chapter, we’ll specifically discuss prioritizing detection requirements, establishing a detection repository, and how to deploy detection code.
We will cover the following main topics in this chapter:
- Revisiting the phases of detection requirements
- Discovering detection requirements
- Triaging detection requirements
- Investigating detection requirements