🛡️ Cyber Defense & SOC · Detection & Purple Team
Engineer detections through a full lifecycle (Splunk)
Ship detection rules like code: versioned, tested, tuned, and retired deliberately.
advanced~40 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1Draft rule from hunt/intel with explicit logic rationale documented
- 2Backtest against 30 days of data; measure raw hit volume
- 3Tune out benign-true noise using environment baselines, not blanket exclusions
- 4Stage: silent-run in prod for one week comparing predicted vs actual hits
- 5Enable with severity matched to expected fidelity; document false-positive budget
- 6Review rule precision quarterly; retire or rewrite below threshold
- 7Version rules in a git-backed ES correlation search repo
- 8Use data models to keep searches acceleration-friendly
Common Pitfalls
- ▲Rules enabled then never revisited until they page falsely
- ▲Exclusions so broad they hollow out the logic
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-splunkInstall globally
$ npx skills add aniruddhaadak80/skills --skill detection-purple-detection-rule-lifecycle-splunk -gTags
#detection-engineering#as-code#cyber-defense-ops#detection-purple