Detection names should describe behaviour, not certainty
Naming a rule "Ransomware detected" promises something it cannot deliver.
It saw a behaviour consistent with ransomware, which is a different claim, and the overstated name shapes how the analyst approaches it before they have looked. A name describing what was observed, such as "many files renamed rapidly by one process", tells the responder what to check and does not prejudge the answer.
More on Detection engineering
- A detection is a hypothesis encoded as logicA guess you can run
- High fidelity and high coverage pull in different directionsOne screen, one setting
- Detections inherit telemetry blind spotsThe hole is copied too
- Suppression is a security decisionThe tag on the switch
- Detection rules need regression testsRun the old cases again
- Behaviour often outlives static indicatorsThe footprints, not the coat
