Skip to content
Home

Detection Engineering

Detection Engineering

A browsable repository of analytics rules. Each entry carries its detection logic, MITRE ATT&CK technique, data sources, the KQL, why it works, likely false positives, and how it was tuned — filterable by technique and data source.

In development

This section is being built out. Here’s what it will hold:

  • 38 analytics rules from a live workspace — deployed definitions, not examples
  • Coverage across identity, Azure control plane, endpoint, and network
  • Each mapped to a MITRE ATT&CK technique with entity mappings
  • Filter by MITRE tactic/technique, data source, and severity
  • The KQL, in copyable code blocks with explanation
  • False-positive notes and recommended improvements per rule

The 38 rules already exist as structured markdown exported from the workspace — severity, cadence, MITRE mapping, entity mappings, and KQL per rule.