Case 718C48 · Blue team / DFIR · L3 Applied
Writing SIEM Detections
Practise as: Explain it · Interview · Deep dive
Interview questionHow do you write and maintain a good detection rule?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Start from a behavior mapped to ATT&CK, not a single IOC; hashes and IPs rotate, TTPs persist.
- Write portable rules in Sigma, then compile to SPL/KQL; version them in git as detection-as-code.
- Test with emulation (Atomic Red Team) for true positives and against baseline data for false positives.
- Track precision, coverage and time-to-detect; tune with scoped allowlists instead of deleting rules.
If the interviewer pushes back
- Design a detection for LSASS credential dumping that survives renamed tools like procdump.
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.