Skip to content

Test-Driven Detection Engineering Framework

Detection engineer · 2025

Built detection content from intelligence and tested intended behavior before production deployment.

Context

Detection content needed to work across QRadar, Splunk and Elastic and arrive with CTI reports and operational notifications.

Problem

MITRE mappings and rule counts did not prove that analytics observed the intended behavior or that supporting logs were available.

Approach

Define tests and expected evidence first, translate Sigma logic through a controlled pipeline, validate the result, and deploy only when the rule passes.

Implementation

  • Derived use cases from threat-intelligence work.
  • Created Sigma-based source logic and platform queries.
  • Validated expected behavior before production promotion.
  • Documented log-source and field gaps when tests failed.

Decisions

Tests before production

A detection is only operational when it observes the intended behavior with usable evidence.

Validation adds work before deployment but reduces false confidence.

Outcome

Rules had to pass a defined test before production. Failed tests also showed which logs or fields were missing.

Platforms & methods

Sigma · QRadar · Splunk · Elastic · MITRE ATT&CK · Detection as Code