All Modules DETECTION ENGINEERING

Detection Engineering · Complete Guide

Eight chapters covering the technical craft of writing, testing, and sustaining detections: reading and comparing KQL, SPL, and Sigma, turning a hypothesis into working detection logic mapped to MITRE ATT&CK, testing with backtests and atomic simulation before deployment, tuning false positives without losing real coverage, building a coverage matrix to find genuine gaps, treating detections like software through version control and peer review, and the metrics that separate a mature detection program from an ad hoc one. Built for analysts and engineers who want to go past reading detection logic to actually writing and maintaining it.

8 CHAPTERS
~12 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
Sigma KQL SPL detection logic false positive tuning ATT&CK coverage detection-as-code rule lifecycle

ALL CHAPTERS

/
01
BEGINNER 25 min

Detection Engineering Foundations

What a detection engineer actually does, how the role differs from a SOC analyst or threat hunter, the detection engineering lifecycle, and the detection-as-code mindset.

detection engineering detection lifecycle detection-as-code
02
BEGINNER 30 min

Query Languages: KQL, SPL & Sigma

The three major detection query dialects, KQL and SPL as platform-native languages, and Sigma as a portable format that converts between them.

KQL SPL Sigma
03
INTERMEDIATE 35 min

From Hypothesis to Detection Logic

Translating an attacker behavior into concrete detection logic, choosing the right data source, field selection, and building logic with thresholds and sequences.

detection logic ATT&CK mapping data sources
04
INTERMEDIATE 35 min

Testing & Validation

Testing detections against historical data and atomic testing before deployment, validating true and false positive rates, and testing safely outside production.

detection testing atomic testing validation
05
INTERMEDIATE 30 min

False Positive Tuning

Root causes of detection false positives, tuning approaches from allowlisting to threshold adjustment, and how to decide between tuning, suppressing, or retiring a rule.

false positive tuning allowlisting alert fatigue
06
INTERMEDIATE 35 min

Coverage Mapping Against ATT&CK

Building a detection coverage matrix mapped to MITRE ATT&CK, finding real gaps versus false confidence, and prioritizing new detections by threat relevance.

ATT&CK coverage gap analysis coverage matrix
07
ADVANCED 35 min

Detection-as-Code & the Rule Lifecycle

Treating detection logic like software: version control, peer review, automated testing pipelines, deployment, and the full lifecycle through deprecation.

detection-as-code version control peer review
08
ADVANCED 30 min

Metrics & Detection Engineering Maturity

Detection engineering KPIs like false positive rate and coverage percentage, how they connect to SOC-wide metrics, and the dimensions that separate a mature program from an ad hoc one.

detection metrics program maturity coverage percentage

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Basic familiarity with what a SIEM and MITRE ATT&CK are (the SOC Operations module's SIEM chapter is a good primer if either is unfamiliar)
  • No prior rule-writing or query-language experience required, Chapter 1 and 2 build that from scratch
  • General comfort with log-based data (fields, events, timestamps) helps but isn't assumed going in
  • No coding background required, this module teaches query and detection logic, not general-purpose programming

WHAT YOU WILL KNOW AFTER

  • How to read and compare KQL, SPL, and Sigma, and when to write in one versus the portable Sigma format
  • How to turn a specific, falsifiable hypothesis about attacker behavior into working detection logic mapped to ATT&CK
  • How to test a detection with backtesting and atomic simulation before it ever reaches an analyst's queue
  • How to diagnose and tune false positives without gutting a detection's real coverage
  • How to build and read an ATT&CK coverage matrix, and prioritize which gaps to close first
  • How detection-as-code (version control, peer review, automated testing pipelines) keeps a growing rule set maintainable
  • What separates a mature detection program from an ad hoc one, and which metrics actually measure that

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.