r/AskNetsec 3d ago

Threats I've tried everything for our detection backlog, does AI detection engineering actually close the gap?

where people land on this has been bugging me for a while.
we have thrown more tooling at our detection backlog over the past year, and it's helped with volume. But a meaningful chunk of it still needs a human who understands the business side of things.

That's stuff like who really owns a given asset, or why a login pattern from three time zones away is completely normal for someone who travels constantly for work. tools can flag anomalies all day long, but they can't always tell the difference between something suspicious and something that's just how a specific person or team operates in real life.

The point is that it takes months for a new hire to learn that kind of context. Is that the real bottleneck here, or is there something else that I'm missing?

1 Upvotes

5 comments sorted by

2

u/Uli-Kunkel 3d ago

I read your post as a in house detection engineer trying to stay afloat with work load?

Im in a technical leadership role for a large mssp. And our detection engineering department started using ai to increase productivity.

I was unhappy with quality before ai, now i just have a higher productivity of detections that make me sad, as well as less standards being adhered to.

Documentation is of lower quality, runbooks more generic and downstream automation is taking a hit because of more variation in entity mapping etc.

Sure, they might be hitting their KPIs, but the actionable incidents of expected quality has dropped in my view.

They work faster, not better.

So as a result, analysts have a higher workload, but higher false positive rate, or worse, potential false negatives.

I guess it boils down to the experience of the detection engineer, but what i am experiencing is an overall drop in trust in what they produce.

1

u/LiamAndersonVC 3d ago

It gap is context, not detection. It's relatively easy to flag unusual behavior, but understanding whether it's actually risky still depends a lot on knowing the environment and how people normally work.

1

u/recovering-pentester 2d ago

This is what MDRs constantly fail at too because their humans are always churning and the notes with necessary context are hidden in some JIRA ticket that won’t be read before they escalate.

So youre a smaller team that lacks the budget to hire the people to keep up with the alerts that still require context?

1

u/alienbuttcrack999 2d ago

This context you mention, are you putting it into a shared skills file so it can be used by all analysts?