A detection is a hypothesis encoded as logic
Every detection is somebody's theory about what an attacker would do, written down in a form a computer can evaluate.
That framing is useful because it makes the assumptions visible. The rule fires when this pattern appears, which assumes the attacker behaves this way, that the relevant data is being collected, and that the pattern is rare in normal use. Any of those can be wrong, and when a detection underperforms it is nearly always one of them rather than the logic.
More on Detection engineering
- High fidelity and high coverage pull in different directionsOne screen, one setting
- Detections inherit telemetry blind spotsThe hole is copied too
- Detection names should describe behaviour, not certaintyName the behaviour
- Suppression is a security decisionThe tag on the switch
- Detection rules need regression testsRun the old cases again
- Behaviour often outlives static indicatorsThe footprints, not the coat
