⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
SOAR Tower • Room 2

Detection Engineering Lifecycle

Detection engineering is the systematic process of creating, testing, and maintaining security detections. The architect establishes the detection lifecycle: Hypothesis (based on threat intel or TTP) → Rule Development (SPL/Sigma) → Testing (against known-bad datasets) → Deployment (via CI/CD pipeline) → Monitoring (alert volume, FP rate) → Tuning/Retirement.

Sigma is an open standard for writing SIEM-agnostic detection rules. The architect may use Sigma rules as the source format and compile them to Splunk SPL, enabling portability and community contribution. This approach decouples detection logic from the SIEM platform.

A detection rule that generates 500 alerts/day with a 99% false positive rate is worse than no rule at all — it trains analysts to ignore alerts. Quality over quantity in detection engineering.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
Complete the detection engineering lifecycle:
Hypothesis → Rule Development → → Deployment → Monitoring →