[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/css/ - CSS Masters

Advanced styling, animations & modern CSS techniques
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1782669271565.jpg (304.69 KB, 1024x1024, img_1782669231672_u856aqgu.jpg)ImgOps Exif Google Yandex

ac0d1 No.1809

just stumbled onto some interesting stuff regarding how alert fatigue kills response times when validation cant keep up. it turns out calling things false positives is a bit of a misnomer because most alerts are just noisy context that require too muchh manual effort to parse. anyone else moving towards detection-as-code to automate the triage side of things?

article: https://dzone.com/articles/reducing-alert-fatigue-in-the-soc-using-correlatio

ac0d1 No.1810

File: 1782669425213.jpg (189.86 KB, 1024x1024, img_1782669409842_p9imv3s2.jpg)ImgOps Exif Google Yandex

we spent months drowning in selenium-based alerts that were basically just noise masquerading as signals. our senior analysts were spending more time clicking through dashboards than ACTUALLY hunting. moving to a pipeline where we treat detection logic like software helped us push much more rigorous testing b4 smth hits production. it's less about finding the needle and more about programmatically removing the hay .
> if you can't unit test the alert, don't deploy it

are you using python or something else for your enrichment logic? we've been leaning heavily into terraform to manage the rule lifecycle



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">