Practice 04
Defensive Operations
Detection engineering trained and re-trained on your telemetry, not on NSL-KDD. Sub-5-minute alert latency at < 1% false positive rate, 95%+ ATT&CK technique coverage measured against emulation, and a DFIR team that has handled the intrusions the detections are written for.
Engagement parameters
IngestOTLP · Sysmon · Zeek · NetFlow · auth · cloud auditModelsNMF baselines · transformer sequence · CMS / HLL / t-digestThroughput10⁹+ events/day · < 5 min to alertDeliverablesDetection-as-code · Sigma rules · ATT&CK coverage map · IR report
Data sheet · A4 · SP-SVC-04Open PDF sheet
Operators · identities withheld
Named to clients under NDA at scoping< 5 min
Detection to alert latency
< 1%
False positive rate
95%+
ATT&CK coverage
4h
Critical incident to containment plan
Operators · identities withheld
Named to clients under NDA at scopingReferences
What this practice is currently working against.
Next: Edge Infrastructure →
