I've been running Firepower Threat Defense for about a year now, primarily for a segmented e-commerce environment. While the dashboard provides plenty of "blocked events" and "correlation alerts," I find these high-level numbers don't truly answer the core question: how effective is it, really, at preventing threats that would have otherwise impacted my network?
I'm looking to move beyond vendor-provided scores and build a more objective, internal measurement framework. In my marketing automation work, we obsess over concrete conversion metrics—I want to apply that same rigor here.
What specific, actionable metrics are you tracking to gauge efficacy? I'm particularly interested in:
* **Detection Accuracy:** How do you quantify false positives vs. true positives? Are you sampling blocked connections for manual review?
* **Prevention Gap Analysis:** For incidents that do occur (e.g., a compromised host), how do you trace back whether Firepower should have caught it earlier in the kill chain? What's your process?
* **Time-to-Mitigation:** Once a new threat intelligence feed or rule is deployed, how do you measure the reduction in malicious connection attempts?
For example, we started logging all "would-have-been-permitted" traffic before critical rules were enabled, then compared it to the blocked traffic afterward. It was revealing.
I'd appreciate any insights on operational metrics you've found valuable, or even simple scripts you use to pull and compare data from FMC.
—Anita