Detections are code, and must follow a lifecycle: Design, Build, Test, Deploy, Tune, and Deprecate.
Testing a detection involves creating dummy data using `makeresults` or replaying PCAP traffic to ensure the alert triggers correctly before moving it to production.