🛡️ Cyber Defense & SOC · Detection & Purple Team
Engineer detections through a full lifecycle (Microsoft Sentinel)
Ship detection rules like code: versioned, tested, tuned, and retired deliberately.
advanced~40 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1Draft rule from hunt/intel with explicit logic rationale documented
- 2Backtest against 30 days of data; measure raw hit volume
- 3Tune out benign-true noise using environment baselines, not blanket exclusions
- 4Stage: silent-run in prod for one week comparing predicted vs actual hits
- 5Enable with severity matched to expected fidelity; document false-positive budget
- 6Review rule precision quarterly; retire or rewrite below threshold
- 7Deploy analytics rules as code via ARM/Bicep pipelines
- 8Watch ingestion latency when setting query frequency
Common Pitfalls
- ▲Rules enabled then never revisited until they page falsely
- ▲Exclusions so broad they hollow out the logic
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-sentinelInstall globally
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-sentinel -gTags
#detection-engineering#as-code#cyber-defense-ops#detection-purple