May 29, 2023

EP123 The Good, the Bad, and the Epic of Threat Detection at Scale with Panther



Topics covered:

  • What is good detection, defined at micro-level for a rule or a piece of detection content? 
  • What is good detection, defined at macro-level for a program at a company? 
  • How to reliably produce good detection content at scale?
  • What is a detection content lifecycle that reliably produces good detections at scale?
  • What is the purpose of a SIEM today?
  • Where do you stand on a classic debate on vendor-written vs customer-created detection content?

