Sigma Rules Planned
Portable detection signatures mapped to adversary techniques.
Detection Engineering
Detection Engineering is an active area of development within this Cyber Threat Intelligence Lab. I am currently studying Practical Detection Engineering and building the foundation for future detection artifacts that connect threat investigations, ATT&CK mapping, telemetry analysis, and defensible detection logic.
Current Status
Future Portfolio
As the capability matures, this section will grow into a portfolio of defensible detection artifacts. Planned content types:
Portable detection signatures mapped to adversary techniques.
Detection and hunting queries for endpoint and network telemetry.
Pattern-based detection for files and malware artifacts.
Evidence that a detection fires on true positives and survives testing.
Detections derived from documented investigation findings.
Coverage tied explicitly to MITRE ATT&CK techniques.
Documented tuning, noise considerations, and limitations for each rule.
Where coverage exists, where gaps remain, and why.
Method
This is the workflow I intend to follow for published detections — the intended future process, not a claim that completed detections already exist.
Investigations → Detections
As this lab develops, selected investigations may later produce corresponding detection artifacts. Those detections will only be published when the logic, assumptions, telemetry requirements, validation steps, and limitations can be clearly documented.
No production-ready detections are published yet. This page exists to document the direction of the work honestly — Detection Engineering is a capability in progress, not a completed portfolio.