What parts of #detection #engineering do people find difficult?
What parts of #detection #engineering do people find difficult?
@timb_machine me: "I only see half the traffic"
me: "wait this is sampled at 1 every 10,000 flows"
me: "oh cute, this biflow only captures the ingress part of the flow and doesn't record the egress interface because it didn't know where it was headed at the time"