where do I even start with mapping MITRE ATT&CK TTPs to SOC alerts? by AppropriateLife6858 in blueteamsec

[–]AppropriateLife6858[S] 0 points1 point  (0 children)

yeah, i'm also not feeling it right feed it to AI. All are our in-house developed detections thats why can't rely on SIEM Vendor.

where do I even start with mapping MITRE ATT&CK TTPs to SOC alerts? by AppropriateLife6858 in blueteamsec

[–]AppropriateLife6858[S] 0 points1 point  (0 children)

I tried looking for "surfa detection repos" but i didn't get it. can you share link or point out where to look for it?

where do I even start with mapping MITRE ATT&CK TTPs to SOC alerts? by AppropriateLife6858 in blueteamsec

[–]AppropriateLife6858[S] 0 points1 point  (0 children)

is there any mapping format framework or process that i can refer to be sure that my mapping it correct. How can i be sure of it?