Skip to content

Field notes

Detection engineering, written down

One technique at a time: the behaviour, the naive rule everyone writes first, why it drowns you, and the tuned version with its test cases.

detection-as-codeci-cd latest

The Detection-as-Code Pipeline That Actually Ships

Most detection-as-code talks stop at 'put your rules in Git'. Here is the rest of it - the lint stage, the unit tests, the deploy gate, and the part nobody mentions: what happens when a rule starts failing in production.

11 min read
mitre-attackmetrics

Your ATT&CK Coverage Map Is Lying to You

A green heat map with 78% coverage is the most comfortable lie in security. Here is why technique counting breaks down, and what to measure instead.

9 min read
windowstelemetry

Sysmon Tuning: Signal Without the Flood

Sysmon out of the box will bury you. A per-event-ID walkthrough of what to keep, what to drop, and how to work out the licence cost before you deploy to 10,000 endpoints.

10 min read