What's changed: Created Professional Security Operations Engineer Chapter 4 (Domain 4 "Detection engineering": reconciling threat intel with activity/detection rules (YARA-L)/reference lists/risk values/Risk Analytics/curated detection rules/SCC Security Health Analytics-posture management/low-prevalence processes-domains-IPs/entity graph/SCC Event Threat Detection custom detectors; IOC-risk alert scoring/searching telemetry with latest IOCs/measuring repetitive-alert frequency to reduce false positives).
4.2Leveraging threat intelligence for detection and reducing false positives
Understand scoring alerts based on the risk level of IOCs, searching ingested security telemetry with the latest IOCs, and measuring the frequency of repetitive alerts to identify and reduce false positives.
Detection is not just about firing alerts. Prioritize alerts with threat intel and reduce false positives so analysts focus on what truly matters.
4.2.1Scoring alerts with IOCs
Score alerts based on the risk level of IOCs and prioritize alerts tied to high-risk IOCs (known C2 servers, infamous malware hashes). To leverage the latest intel, search ingested security telemetry with the latest IOCs, finding matches lurking in past/present data. Analyst time is finite, so order by risk and handle in "most-impactful-first" order. Map "prioritize alerts tied to high-risk IOCs = score by IOC risk."
4.2.2Identifying and reducing false positives
Noisy detections exhaust analysts and let real threats slip. Measure the frequency of repetitive alerts to identify chronic false positives, and reduce them by tuning rules (narrow conditions, exclude known-good, allowlist via reference lists, adjust thresholds). Lowering the false-positive rate raises detection "precision," letting analysts focus on truly important alerts. Map "measure and cut constantly firing alerts = reduce false positives."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

