Five lessons I learned from building anomaly-based threat detection

Alex Teixeira
Detect FYI
Published in
4 min readAug 30, 2023

--

This is a short one for inspiring those planning or already adventuring with anomaly detection as part of their use cases backlog.

Anomaly-based detection is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations.

Above definition is from Security Controls Evaluation, Testing, and Assessment Handbook (2016)…

--

--

I design and build threat detection and triage/hunting SIEM/EDR/XDR content for Enterprise #SecOps teams #DetectionEngineering http://opstune.com