Detection is the phase of the defensive lifecycle where an organization discovers that something malicious or anomalous is happening. It sits between preparation, which builds the groundwork, and response, which acts on what detection surfaces. Strong detection shortens the time an adversary can operate unnoticed and gives responders the signal they need to act. It depends on good visibility, sound logic, and people who understand what normal looks like so they can recognize what does not.
This pillar covers the capabilities that turn raw activity into actionable signal.
- Collection gathers telemetry and log sources from endpoints, networks, identity systems, and cloud platforms so that activity is recorded and available for analysis.
- Analysis applies correlation and detection logic across that telemetry to separate meaningful events from background noise.
- Alerting routes confirmed or suspicious findings to the right people and systems with enough context to act.
- Threat hunting proactively searches for adversary activity that automated detections may have missed.
- Deception uses honeypots and decoys to lure and reveal intruders while generating high-confidence signals.
- Detection engineering designs, tests, and maintains the rules and analytics that power detection.
- Continuous improvement measures detection coverage and tunes it as threats and the environment change.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- SANS Institute, detection and threat hunting resources