Summary
In this chapter, we discussed the concept of data sources as they relate to detection engineering. Fully understanding your data sources is an integral part of detection engineering – without good data, you can’t develop quality detections. Furthermore, gaps in data sources being received will also result in gaps in detections. We ended this chapter by adding a couple of new data sources to our detection lab, specifically Apache web server logs and network packet capture data.
In the next chapter, we’ll dive into workflows and technologies that enable us to efficiently design, develop, and maintain detections.