SOC redesign at an international group
Rebuilding security monitoring at an international group: data sources consolidated, use cases prioritised, and daily threat hunting established.
An international group had security monitoring that collected data but detected little. The rebuild therefore started not with the platform but with the sources and the use cases.
Starting position and scope
A rebuild of the detection on the existing platform.
Environment
An international group with a landscape grown over time, several sites and a considerable number of connected systems.
Problem
The existing monitoring collected log data on a large scale but produced few alerts anyone followed up. Analysts worked mostly reactively on messages without context.
Approach
Consolidate the data sources, prioritise and develop use cases, establish threat hunting as a permanent part of the work.
Collecting is not detecting
A SIEM that takes in everything produces cost and noise. Without normalisation, events from different sources cannot be correlated sensibly, and without prioritised use cases it is chance that decides what stands out.
So the first task was to order the sources: which are needed, which are missing, and which only produce volume.
From the sources to the hunt
In that order, because each step is the basis of the next.
Consolidate the sources
An inventory of the connected systems, normalisation onto a common schema, enrichment with asset and identity context.
Prioritise use cases
Not everything at once. Priority followed the techniques realistic for this environment, and what is detectable at all with the sources available.
Develop and measure the detection
Rules versioned, measured against their coverage and tuned. What produced too many false positives was sharpened rather than switched off.
Establish threat hunting
A daily hypothesis-driven search whose results flow back into the use cases. That turns detection into a cycle rather than a state.
What changed measurably
The number of alerts went down and the share of those worked on went up. Analysts were no longer mostly clearing warnings but working on hypotheses. And the coverage could be quantified for the first time rather than asserted.
The most important effect was organisational: use case development became a permanent task of its own. Without it, any monitoring falls behind over the years.
What you can take from this
Changing SIEM rarely solves the problem it gets blamed for. In most cases the cause lies with the sources and with missing use case work, and both survive a change of platform unchanged.
Anyone who does not measure coverage does not know what they detect. Mapping the rules onto a tactics and techniques model is the simplest way to make that question answerable.
Threat hunting supplies the feedback from which new use cases come.
Related to this case study.
A similar project?
Referenzdetails nennen wir nach Freigabe und im persönlichen Gespräch.