keeping all versions of rules in separate git repos was confusing to the SOC and made finding info about a detection hard.
Now we have a one repo in a single language, with a wiki containing rule info like goal, investigation tips, prebuilt queries, references, FPs, etc.
🧵2/3
We are still solutioning how we are going to track translation and deployment to each platform and client. @NotionHQ seems to be the frontrunner for that endeavor.
🧵3/3
• • •
Missing some Tweet in this thread? You can try to
force a refresh