Threat model first, tooling second
Threat model first, tooling second
Teams adopt detection platforms before they can describe the adversary. We walk through the five questions we ask every client before we touch a single rule.
The tooling trap
The most common failure we see is not a lack of tooling — it is tooling bought ahead of understanding. A team installs an enterprise detection platform, configures a vendor's default rule set, and then cannot say which adversary it is defending against. The platform becomes an asset-management project, not a security program.
Tooling amplifies a posture; it does not create one. A detection platform with no threat model produces noise. A threat model with basic tooling produces a focused program.
Five questions before any rule
The answers do not need to be perfect. They need to be written down, shared, and argued with. The point is that when a rule fires, someone can say whether it matters — against an explicit opponent and an explicit asset.
- Who is the adversary we are most worried about, and what do they want?
- What assets, if lost or exposed, would hurt most?
- Which attack paths would an adversary most plausibly take?
- What do we already detect today — and what are we blind to?
- What telemetry would change the picture, and can we collect it?
Where the platform comes in
Once the model exists, the tooling decisions become obvious: what to monitor, what to alert on, how to tune, and what to retire. The same budget that bought a wall of dashboards buys a handful of rules that map to an actual attack path.
Bottom line
Before you buy another platform, write down who you are defending against and what an attack looks like. The tooling survives the strategy; the strategy rarely survives a tool-first choice.

