Five Ws: Who, what, when, where, and why.
AC = Total Count of Alerts ReceivedFPR = False Positives / Total AlertsAER = Escalated Alerts / Total AlertsTDR = Detected Threats / Total ThreatsSLA: document signed by internal SOC team and company management or my MSSP and its customers.
Ways to improve: exclude system updates and trusted activities. Automate alerts using custom scripts, tune detection rules, make sure logs are being collected in real-time without a delay. Evenly distribute alerts between analysts. Escalate as quickly as possible, use workbooks.
Workbooks: defines step required in an investigation.
Endpoint Detection and Response.
Visibility:
