Home
Detection Engineering
Detection Engineering
A browsable repository of analytics rules. Each entry carries its detection logic, MITRE ATT&CK technique, data sources, the KQL, why it works, likely false positives, and how it was tuned — filterable by technique and data source.
In development
This section is being built out. Here’s what it will hold:
- 38 analytics rules from a live workspace — deployed definitions, not examples
- Coverage across identity, Azure control plane, endpoint, and network
- Each mapped to a MITRE ATT&CK technique with entity mappings
- Filter by MITRE tactic/technique, data source, and severity
- The KQL, in copyable code blocks with explanation
- False-positive notes and recommended improvements per rule
The 38 rules already exist as structured markdown exported from the workspace — severity, cadence, MITRE mapping, entity mappings, and KQL per rule.