Detection Engineering

Turn a detection requirement into a deployed, tested, versioned rule — with a benign twin that must NOT fire, an explicit false-positive budget, a volume estimate before deploy, and a tuning history that records every silently narrowed scope. Use whenever the user writes or reviews an alert, a Sigma/KQL/SPL/EQL/YARA rule, a SIEM correlation search, a WAF or EDR policy, an anomaly threshold, or a monitor that pages someone; whenever they say "write a rule for this", "alert when X", "we're getting too many alerts", "tune this detection", "why didn't this fire", "detection as code", or "add a monitor"; and whenever a purple-team gap needs closing. Sibling of purple-team-exercise — that skill specifies WHAT must be caught, this one builds and proves the thing that catches it. It does not run exercises, does not triage incidents, and never claims coverage from a rule that has not fired on a real true positive.

annatchijova 9d5d0bf 12.7 KB Updated

File contents

annatchijova/SKILLS/tree/main/detection-engineering commit 9d5d0bff04

Frequently asked questions

npx skillmds@latest add annatchijova/detection-engineering