Security Analytics: How to rank use cases based on the "Quick Wins" approach?

Alex Teixeira
8 min readApr 18, 2017

When planning for a Security Monitoring project, no matter if it’s a rule that triggers alerts or an interactive dashboard to support hunters, once you have gathered an initial set of feasible ideas, where to start?

A Quick Win is commonly referred to as the result of “High Value” plus “Low Effort” combo. In practice, here's how I…

--

--

Alex Teixeira

I design and build threat detection and triage/hunting SIEM/EDR/XDR content for Enterprise #SecOps teams #DetectionEngineering http://opstune.com