Notifications
Clear all
Endpoint / EDR / XDR
1
Posts
1
Users
0
Reactions
2
Views
Topic starter
16/07/2026 10:04 am
Starting a new EDR deployment. The vendor's "baseline" config has 150+ detection policies enabled by default. This is insane.
My team is small. We can't triage 150 different alert types out of the gate. Alert fatigue will set in before we log into the console.
So, what's the real number? I'm thinking:
* Start with the top 10-15 MITRE ATT&CK techniques relevant to our vertical.
* Enable policies for blatant malice (ransomware behavior, C2 beaconing).
* Add 2-3 for our crown jewel assets.
* Everything else stays in audit/logging mode for the first 30-90 days.
Is this too conservative? I'd rather have 10 policies we respond to in 10 minutes than 150 we ignore.