Test-Driven Detection Engineering Framework
Detection engineer · 2025
Built detection content from intelligence and tested intended behavior before production deployment.
Context
Detection content needed to work across QRadar, Splunk and Elastic and arrive with CTI reports and operational notifications.
Problem
MITRE mappings and rule counts did not prove that analytics observed the intended behavior or that supporting logs were available.
Approach
Define tests and expected evidence first, translate Sigma logic through a controlled pipeline, validate the result, and deploy only when the rule passes.
Implementation
- Derived use cases from threat-intelligence work.
- Created Sigma-based source logic and platform queries.
- Validated expected behavior before production promotion.
- Documented log-source and field gaps when tests failed.
Decisions
Tests before production
A detection is only operational when it observes the intended behavior with usable evidence.
Validation adds work before deployment but reduces false confidence.
Outcome
Rules had to pass a defined test before production. Failed tests also showed which logs or fields were missing.
Platforms & methods
Sigma · QRadar · Splunk · Elastic · MITRE ATT&CK · Detection as Code