BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//talk//VVKWCX
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250925T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Detection in Technicolour: Finding the Gaps Your Dashboard Cannot 
 See - Zafer Balkan
DTSTART;TZID=Europe/Helsinki:20260925T110000
DTEND;TZID=Europe/Helsinki:20260925T114500
DTSTAMP:20260926T112156Z
UID:pretalx-bsides-tallinn-2026-VVKWCX@pretalx.com
DESCRIPTION:Security teams measure what their detection systems produce: a
 lerts\, incidents\, false positives\, response times\, and technique cover
 age. These metrics are useful\, but they describe only what became visible
 . They tell us much less about telemetry that was never generated\, never 
 collected\, rejected during parsing\, stripped of context during normaliza
 tion\, or delivered too late to support a detection.\n\nDashboards make th
 is limitation easy to overlook. They show ingestion rates\, parser success
 \, rule activity\, and correlation volume in reassuring colour. Yet a high
  parse-success rate excludes anything rejected before the parser recorded 
 it. Low ingestion latency does not tell us whether the right events were c
 ollected. A rule that fires regularly may be healthy\, or it may simply be
  seeing the small part of the environment that still produces usable evide
 nce. We often use measures of pipeline activity as evidence of detection c
 overage.\n\nEvery detection system works within a blindness budget. Collec
 tion capacity is finite. Parsing accuracy requires engineering effort. Lon
 ger retention consumes storage that might otherwise support faster access 
 or broader collection. Near-real-time detection often acts on incomplete e
 vidence. Correlation depends on fields retaining stable meaning after they
  have passed through several systems. A decision that appears reasonable a
 t one stage can remove options from the next\, with no visible failure unt
 il a detection is missed.\n\nThis talk follows security telemetry through 
 a production SIEM stack\, from generation and collection to parsing\, norm
 alization\, storage\, correlation\, hunting\, and detection. It brings tog
 ether three views that are usually discussed separately: the architect dec
 iding where state\, trust\, and failure boundaries belong\; the developer 
 implementing the pipeline and its instrumentation\; and the detection engi
 neer depending on that pipeline to preserve enough evidence for a rule to 
 work. Looking at the same system from all three perspectives exposes failu
 res that remain hidden when each layer is assessed in isolation.\n\nMissin
 g telemetry is only one part of the problem. Analysts adapt to the alert s
 treams they receive. When false positives and repetitive alerts dominate\,
  dismissal becomes a rational response to limited attention. Rules continu
 e to fire\, but trust declines. Investigations become shallower\, and aler
 ts remain open without meaningful action. Too little evidence and too much
  noise reach the same operational result through different mechanisms.\n\n
 The talk uses six working categories for examining missed detections: coll
 ection gaps\, parsing gaps\, data-quality failures\, semantic loss\, corre
 lation failures\, and detections that never received enough evidence to fi
 re. The boundaries are not always clean. A malformed event may appear to b
 e a parsing problem\, a schema problem\, or a collection problem depending
  on where measurement begins. The useful question is not which label fits 
 best\, but where the evidence disappeared and whether the pipeline can dem
 onstrate that it was present.\n\nAttendees will see how to assess telemetr
 y freshness\, parser health\, schema completeness\, ingestion delay\, corr
 elation readiness\, unknown-event rates\, rule dependencies\, orphaned rul
 es\, and signs of analyst fatigue. These measurements do not produce a com
 plete account of detection quality\, but they expose failures that convent
 ional SOC dashboards usually hide.\n\nThe question is not whether the pipe
 line is active. It is whether enough of the right evidence survives the pi
 peline to detect anything that matters.
LOCATION:Stage B
URL:https://pretalx.com/bsides-tallinn-2026/talk/VVKWCX/
END:VEVENT
END:VCALENDAR
