Eight chapters covering the technical craft of writing, testing, and sustaining detections: reading and comparing KQL, SPL, and Sigma, turning a hypothesis into working detection logic mapped to MITRE ATT&CK, testing with backtests and atomic simulation before deployment, tuning false positives without losing real coverage, building a coverage matrix to find genuine gaps, treating detections like software through version control and peer review, and the metrics that separate a mature detection program from an ad hoc one. Built for analysts and engineers who want to go past reading detection logic to actually writing and maintaining it.
No chapters match “”.
What a detection engineer actually does, how the role differs from a SOC analyst or threat hunter, the detection engineering lifecycle, and the detection-as-code mindset.
The three major detection query dialects, KQL and SPL as platform-native languages, and Sigma as a portable format that converts between them.
Translating an attacker behavior into concrete detection logic, choosing the right data source, field selection, and building logic with thresholds and sequences.
Testing detections against historical data and atomic testing before deployment, validating true and false positive rates, and testing safely outside production.
Root causes of detection false positives, tuning approaches from allowlisting to threshold adjustment, and how to decide between tuning, suppressing, or retiring a rule.
Building a detection coverage matrix mapped to MITRE ATT&CK, finding real gaps versus false confidence, and prioritizing new detections by threat relevance.
Treating detection logic like software: version control, peer review, automated testing pipelines, deployment, and the full lifecycle through deprecation.
Detection engineering KPIs like false positive rate and coverage percentage, how they connect to SOC-wide metrics, and the dimensions that separate a mature program from an ad hoc one.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Detection rule library across KQL, Sigma, and XQL. The direct reference point for the query-language literacy covered in Chapter 2 and the logic patterns covered in Chapter 3.
Hunting hypothesis matrix. A working example of the specific, falsifiable hypothesis framing Chapter 3 asks you to write before touching a single field.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB. Useful for the threat-relevance factor in Chapter 6's gap-prioritization work.