Open cardosec

Case 718C48 · Blue team / DFIR · L3 Applied

Writing SIEM Detections

Practise as: Explain it · Interview · Deep dive

Interview questionHow do you write and maintain a good detection rule?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Start from a behavior mapped to ATT&CK, not a single IOC; hashes and IPs rotate, TTPs persist.
  2. Write portable rules in Sigma, then compile to SPL/KQL; version them in git as detection-as-code.
  3. Test with emulation (Atomic Red Team) for true positives and against baseline data for false positives.
  4. Track precision, coverage and time-to-detect; tune with scoped allowlists instead of deleting rules.

If the interviewer pushes back

  • Design a detection for LSASS credential dumping that survives renamed tools like procdump.

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.