Thanks all!
Ill be the first to ask, you mention your internal security agent stack, what does it look like?
I doubt its analyzing every event from SIEMs and other security systems, so is it a soc triage stack or is it more - and how are you tuning it after its miss?