Index / Detection and tuning
Detection and tuning
Policy design, false positives, behavioural analytics and the major egress channels.
- ProcedureTuningPolicy Design: Start in Monitor Mode and Stay There Longer Than Feels ComfortableThe sequence from observation to enforcement, and why organisations that skip it end up enforcin
- ProcedureTuningThe False Positive ProblemEvery DLP deployment drowns at first. What causes it, how to reduce it, and why the usual respon
- ExplainerAnalyticsBehavioural Analytics: What It Can and Cannot Tell YouUser behaviour analytics is sold as detection of intent. It detects deviation from a baseline, w
- ReferenceEgressEmail and Web EgressThe most instrumented channels and still the largest source of incidents. What to watch and what
- ReferenceEndpointEndpoint and Removable MediaWhat the agent sees that the network cannot, and the controls that are worth the friction.
- ReferenceCloudCloud and SaaS Data MovementThe largest modern egress route and the least instrumented. Sharing links leave almost no trace
- ReferenceIPProtecting Source Code and Intellectual PropertyUnstructured IP is what content inspection is worst at, and frequently what matters most. What w
- ProcedureApplicationsDetecting Bulk Export From Systems of RecordThe highest-consequence movements start with someone downloading a large extract. The logs usual
- ProcedureAnalyticsAlert Enrichment: The Context That Makes Triage PossibleA raw alert is uninterpretable. The same alert with five fields of context takes thirty seconds
- ChecklistAssuranceTesting Your Own ControlsMost programmes have never verified that their detections fire. The ones that test find gaps imm
- ProcedureTuningDetection Engineering as a PracticeTreating detections as maintained artefacts rather than one-time configuration is what separates