Detection Engineering Threat Hunting

Detection engineering and threat hunting: detection-as-code with Sigma rules in version control, log pipeline and telemetry source coverage, MITRE ATT&CK coverage mapping, alert precision and tuning to survive analyst trust, validation with Atomic Red Team, and hypothesis-driven hunts for activity that evaded automated controls. Use when security alerts are too noisy to act on, when deciding which detections to write and which telemetry to collect first, or when hunting for attacker activity nothing has alerted on.

mchittineni Updated

File contents

mchittineni/cloud-platform-skills/tree/main/.agents/skills/detection-engineering-threat-hunting commit a230361356

Frequently asked questions

npx skillmds@latest add mchittineni/detection-engineering-threat-hunting