Francesco Faenzi’s Post

View profile for Francesco Faenzi, graphic

#TrustEverybodyButCutTheCards

Living off the #FalsePositive for #CyberThreat #DetectionEngineering #TrustEverybodyButCutTheCards LoFP is an autogenerated collection of false positives sourced from some of the most popular rule sets. The information is categorized along with #MITREATTACK techniques, rule source, and data source. Entries include details from related rules along with their description and detection logic. The goal is to enable both red and blue teams with this information: - #Redteams can use this information to blend in - #blueteams can use this information to assess weak spots in their #detectionlogic and also as an assistant during alert #triage and #investigation, by looking at common FPs around certain techniques and data sources. For more details, checkout the release #blog https://lnkd.in/dCtE_gS3. #TrustEverybodyButCutTheCards

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics