The Detection Engineering Workbench treats rules as software. A detection begins with an adversary behavior and data requirement, is tested on representative events, and carries review context through to deployment and tuning.
Project signal
Rule as code
from hypothesis to release
Core stack
Sigma · GitHub Actions · Python · YAML
Architecture
Captures the analytic hypothesis, expected data source, false-positive assumptions, and ATT&CK technique.
Runs positive and negative event samples against the detection before review.
Publishes reviewed logic with changelog notes, owner metadata, and a planned tuning checkpoint.
Capabilities
Operational views
These interface snapshots define the key evidence surfaces for the project. They are intentionally designed around investigation context rather than decorative dashboards.
View 01
Captures the analytic hypothesis, expected data source, false-positive assumptions, and ATT&CK technique.
View 02
Runs positive and negative event samples against the detection before review.
View 03
Publishes reviewed logic with changelog notes, owner metadata, and a planned tuning checkpoint.
Roadmap
Continue exploring
SOC Engineering
A detection-first SOC operations workspace that brings telemetry health, triage context, and response playbooks into one deliberate workflow.
Home Lab
A repeatable Windows and Linux monitoring lab for testing telemetry, adversary behavior, and detections before production use.
Threat Hunting
A hypothesis-led investigation framework for turning ATT&CK-informed questions into repeatable hunts and measurable improvements.