

EP202 Beyond Tiered SOCs: Detection as Code and the Rise of Response Engineering
19 snips Dec 9, 2024
Amine Besson, Tech Lead on Detection Engineering at Behemoth Cyberdefence, shares his insights on the evolution of security operations and the importance of detection engineering. He discusses the inadequacies of traditional tiered SOCs against modern threats and introduces 'detection as code' as a transformative approach. Amine also elaborates on the fusion of threat intelligence with detection and response, stressing real-time actionable insights. Finally, he highlights new architectures like OpenTIDE that enhance threat detection and efficiency.
AI Snips
Chapters
Transcript
Episode notes
SOC Ownership
- Consider the level of ownership you want over your SOC.
- Owning efficiency means understanding your technology and content.
SOC Evolution
- The term "SOC" is becoming outdated, evolving into "Cyber Defense Center."
- The focus is shifting from tiered structures to expert teams.
Innovation in Detection Engineering
- Well-funded companies lead innovation in detection engineering.
- Smaller companies are starting to adopt it, showing a shift in the industry.