1. Home
  2. Insights
  3. Threat detection
Threat detection

Detection is a tuning problem, not a tool problem

When detection fails, the instinct is to blame the platform. In our experience the platform is rarely the problem. The problem is that nobody owns the quality of what it produces, so it slowly becomes noise that everyone learns to ignore.

The muting death spiral

Every rule needs an owner and a reason

Measure precision, not rule count

Map to ATT&CK so you can see the holes

Telemetry first, rules second

Triage is a skill, not a queue

What good looks like

  • A small number of rules, each with an owner, a reason and a review date
  • An alert-to-investigation ratio that analysts trust
  • ATT&CK coverage you can show and a plan for the gaps
  • A named human on call, with an agreed response time
  • A monthly review that removes as much as it adds

Start with the gaps, not the shopping list.

Book a 30-minute review. We will look at what you have and tell you the three things worth doing first.

Book a security review