Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

Detection Engineering

Sample Snort rules worth borrowing for a new SOC

Last year I priced network detection for a greenfield SOC and learned the buying part was easy. The Talos ruleset was $399 a sensor, ET Open was free, and the free set alone ran to tens of thousands of rules. Purchasing was the easy part; curation was the real job.

DCDaniel C. · Aug 28, 2026
Compliance and Risk

ISO compliance mapping: from the SecOps seat

ISO 27001 mapping rarely begins with a missing SOC capability. The trigger is usually a customer request, a 93-control Annex A spreadsheet, and a harder question: can I prove what my SOC actually does? The answer lives in evidence, ownership, and an honest Statement of Applicability, not a SIEM screenshot.

DCDaniel C. · Aug 28, 2026
Identity & Access Security Operations

Ping SSO logs the SOC can't afford to skip

I stopped treating Ping as one SSO log source after watching a PingOne feed look healthy while missing the one field a detection needed. PingOne and PingFederate use different collection paths, schemas, and defaults. Before I build any identity detection now, I validate the raw fields the rule depends on, starting with source IP.

DCDaniel C. · Aug 28, 2026
Identity & Access Security Operations

Privileged access in 2026: from the investigation seat

I've led the review after every serious incident my teams handled in a decade. The board always asks how it got this bad, and the answer is rarely the initial phish; it's the next step, when the attacker gains the authority to reset MFA, change roles, and export data.

DCDaniel C. · Aug 22, 2026
Threat Hunting

A hunt we ran that found nothing, and why it mattered

I closed the ticket in about nine minutes. Weeks later an intel report made me reopen it as a by-hand hunt against old logs. The hunt found nothing, and that empty result was worth more than most of the true positives I have escalated.

MKMarta K. · Aug 22, 2026
AI in Security Operations

The three root causes of alert fatigue in cybersecurity, and where AI actually helps

I've sat through eight AI SOC demos, each promising to end my team's alert fatigue. By the third I was asking one question first: which part? Too much volume, low-fidelity alerts, and no clear ownership are three different problems, and most demos treated them as one.

DCDaniel C. · Aug 22, 2026
AI in Security Operations

Alert fatigue is a detection-pipeline problem, not an analyst failure

A post-incident review took forty minutes to decide an analyst had missed an alert. Her queue held more than 800 alerts that shift, many of them duplicate copies of the same signal. She did not build that queue; the detection pipeline did.

MKMarta K. · Aug 22, 2026
SOC Modernization

SIEM in cyber security is a logging tax, not a detection strategy

At my last fintech, every endpoint, identity provider, and cloud account fed the SIEM. An attacker still moved laterally for two days without triggering a rule. The logs were present; the detection engineering was not.

MKMarta K. · Aug 22, 2026
Detection Engineering

Tuning detections to cut false positives without killing coverage

My team wanted a noisy recon rule disabled. I pulled six months of its history first and found one true positive: the early recon phase of a red team engagement we'd paid for. Here's how I tune a rule like that instead of killing it.

MKMarta K. · Aug 17, 2026