Kai Ole Hartwig

name of the term: Threat Detection
descriptions of the term:

Definition

Definition. The task of filtering, correlating and prioritising security-relevant events from logs, metrics, traces and runtime sensors, whether rule-based, statistical or model-based. The result is manageable alerts with context, not raw logs.

Why it matters. At mid-sized companies, the quality of detection often matters more than the number of tools. A few precise alerts with clear playbooks are manageable. A stream of unsorted events is not.

Related. Runtime Security, Falco, Tetragon, DevSecOps

Type of term: definition
Language of the term (2 char ISO code): en
Back