SIEM & Detection Engineering
How an adversary behaviour becomes a rule that survives real data: picking the observable, writing correlation and rarity logic over it, and keeping it firing after it ships.
on this pageshowhide
explore
- From Behaviour to Signal16 questions
- Choosing the Observable4 questions
- Indicator or Behaviour4 questions
- Labelling With Techniques4 questions
- Inputs a Rule Assumes4 questions
- Expressing the Logic11 questions
- Joining Events in Time3 questions
- Rarity and First Seen4 questions
- Search Language Idioms4 questions
- After It Ships12 questions
- Portable Rule Formats4 questions
- Tuning Without Going Blind4 questions
- A Rule Gone Quiet4 questions
questions
page 2 of 2Why does a 40,000-entry indicator list in a SIEM search cost more to run than one behavioural clause?
basics
~20 sThe list match has no selective predicate: every record must be tested against it on every scheduled run, so cost tracks total traffic volume and grows with the list. A behavioural clause narrows the records first.
What does a synthetic canary event injected to make a detection fire actually prove?
basics
~20 sOnly that the path from the injection point to the alert works: parsing, indexing, the schedule, the rule's logic against today's fields, and routing. It proves nothing upstream of where it was injected, and nothing about real adversary behaviour.
How can an asset-owner lookup inside a scheduled SIEM detection create a blind spot?
basics
~20 sEvents whose key is missing from the lookup come back with the enriched fields empty, and any later filter on those fields drops them. Unregistered assets never alert, while the rule keeps firing elsewhere and looks healthy.
As SIEM platform owner, how do you answer a detection engineer who wants a correlation window widened to six hours?
basics
~20 sAnswer with a price and alternatives, not yes or no. Held state scales with the first stage's event rate times the window, so ten minutes to six hours is roughly thirty-six times more. Seek the same coverage cheaper first.
When do you record an adversary behaviour as undetectable rather than ship a rule that cannot match it?
basics
~20 sWhen no collected field separates the behaviour from normal work on the sensors you have. Write it up as a dated gap with the specific change that would fix it, because a rule that cannot fire still reads as coverage and stops anyone asking again.
A fleet owner refuses your auditd watch on 40% of hosts. What do you ship, and what coverage do you claim?
basics
~20 sShip the rule scoped to hosts where the prerequisite is proven, state coverage as that host set, and make the remainder a named gap with an owner. Try to buy coverage back by narrowing the watch.
A platform team owning your Kubernetes audit feed wants their engineers' debug execs out of a report tagged with an adversary technique — how do you respond?
basics
~20 sConcede the report, not the label or the feed. A technique identifier is a taxonomy of what a rule looks for, and it should never appear beside a named engineer in a management report. Then remove the friction: give authorised execs an attributable path so they close themselves.
An MSSP delivers detections as Sigma but your team owns the SIEM. Who owns the field mapping?
basics
~10 sSomeone has to own it by name, in the contract. The author holds the logic without your data, you hold the data without their intent, so "deployed" must mean converted, mapped and observed firing.
A profiler your team cannot ban keeps tripping a memory-read detection on developer laptops — what do you propose?
basics
~20 sSplit the estate: keep the strict rule where the behaviour has no legitimate producer, and run a narrow, expiring exception on the laptop fleet whose residual risk is accepted in writing by the engineering owner rather than absorbed silently by security.
showing 31–39 of 39