The Hunt That Found Nothing
An advisory lands, you sweep the estate, nothing comes back. A fleet-wide clean result has a numerator and no denominator, which is not the same as safe.
Read more →Blog › Detection Engineering
Detection rules that survive contact with production: what a rule actually fires on, how to measure coverage against ATT&CK, and how to tune without losing the true positives. KQL, Sigma and SPL, side by side.
15 articles
An advisory lands, you sweep the estate, nothing comes back. A fleet-wide clean result has a numerator and no denominator, which is not the same as safe.
Read more →Brute force and password spray produce the same failed sign-in event. A per-account threshold catches one and misses the other entirely.
Read more →A one-character field typo passes sigma check, converts to valid KQL and SPL, and matches nothing. Static validation cannot prove a rule works.
Read more →Detect T1053.005 scheduled task persistence with KQL, SPL and Sigma, using Event ID 4698 and a scoring model that separates attacker tasks from admin ones.
Read more →IP and domain indicators expire within days. The interval a beacon sleeps on does not. How to score connection cadence in Sentinel and Splunk.
Read more →Alerting on AssumedRole from outside AWS buries you in SSO noise. Here is the marker that isolates a stolen EC2 instance credential from the rest.
Read more →The fastest way to quiet a noisy rule is to exclude the field making the noise. It is also the fastest way to cut a hole the attacker walks through.
Read more →Ten KQL queries against SigninLogs that answer what SOC analysts actually ask during an identity investigation, copy-paste ready with annotated output.
Read more →Most detection libraries are full of rules that have never fired. Silent rules are not coverage, they are assumptions. How to find and validate them.
Read more →LSASS dump detection is table stakes. Kerberoasting, DCSync, DPAPI abuse, SAM extraction, and token theft each need different KQL.
Read more →Most organizations can't prove their detection program works. Here's what effective looks like and the four numbers that prove it.
Read more →KQL sign-in log analysis: what ResultType values mean, how to detect password spray, MFA fatigue, and CA blocks in Sentinel.
Read more →Your detection rules cover known patterns. These five KQL hunts find the attacker activity that bypasses every analytics rule in your library.
Read more →Microsoft ships 200+ Sentinel rule templates but leaves gaps in mailbox abuse, consent grants, and privilege escalation. Five rules to build.
Read more →Most Linux rootkits load as kernel modules. Five auditd rules that detect module loading, modification, and persistence techniques.
Read more →Other topics