Cloud Security Podcast by Google

EP241 From Black Box to Building Blocks: More Modern Detection Engineering Lessons from Google

7 snips
Sep 1, 2025
Rick Correa, Uber TL for Google SecOps and expert in detection engineering, shares his journey of scaling curated detections from a mere 70 to over 4,700 rules. He discusses the pivotal lessons learned and the importance of user-friendly interfaces to alleviate customer friction. The conversation dives into the distinction between 'Detection-as-Code' and advanced software engineering practices, emphasizing the need for unit testing and performance reviews. Correa introduces the 'Goldilocks Zone' for detections and provides practical examples of building blocks for enhancing security against threats like VPN and Tor traffic.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ANECDOTE

Scaling By Enabling Many Authors

  • Rick describes scaling from ~70 to ~4,700 rules by enabling many contributors after the Mandiant-Google merge.
  • He built IDE-like tooling and submission flows so hundreds of engineers could author testable rules.
INSIGHT

Make Contribution Frictionless

  • Standardization plus linting prevents divergent contributions as author count grows.
  • An IDE-like authoring experience and play/test/submit flow reduced onboarding friction.
INSIGHT

Transparency Enables Customer Extension

  • Transparency matters: moving curated content into a marketplace lets customers see and extend rule logic.
  • Opaque rules remain only when necessary for embargoed or secret telemetry.
Get the Snipd Podcast app to discover more snips from this episode
Get the app