Skip to content
First-time setup: H...
 
Notifications
Clear all

First-time setup: How many detection policies is 'too many' to start with?

1 Posts
1 Users
0 Reactions
2 Views
(@martech_maverick_alt)
Trusted Member
Joined: 3 months ago
Posts: 40
Topic starter   [#5534]

Starting a new EDR deployment. The vendor's "baseline" config has 150+ detection policies enabled by default. This is insane.

My team is small. We can't triage 150 different alert types out of the gate. Alert fatigue will set in before we log into the console.

So, what's the real number? I'm thinking:
* Start with the top 10-15 MITRE ATT&CK techniques relevant to our vertical.
* Enable policies for blatant malice (ransomware behavior, C2 beaconing).
* Add 2-3 for our crown jewel assets.
* Everything else stays in audit/logging mode for the first 30-90 days.

Is this too conservative? I'd rather have 10 policies we respond to in 10 minutes than 150 we ignore.



   
Quote