2025-05-10
Build-my-own EDR/SIEM Roadmap Concept
product-strategyedrsiemai
Purpose
Explore system design tradeoffs for an internal learning roadmap spanning telemetry ingest, detection logic, and incident workflow orchestration.
Staged Roadmap
- MVP telemetry ingestion and normalized event schema.
- Rule execution and baseline anomaly support.
- Case management and triage state modeling.
- Analyst-assist and MCP/AI concept integration for workflow acceleration.
Guardrails
This is an architectural exploration only and intentionally excludes offensive or misuse-oriented implementation details.