Back to Resources
Detection Engineering Guide: visual preview
Guide

Detection Engineering Guide

Sigma Rules, MITRE ATT&CK & Detection-as-Code Practice

Overview

Detection engineering is the discipline of systematically building, testing, deploying, and maintaining threat detection capabilities. It moves detection from an art practiced by a few senior analysts to an engineering discipline with version control, testing, and measurable quality metrics. This guide covers the detection lifecycle, Sigma rule development, ATT&CK coverage mapping, and the practices that make detection-as-code work at scale.

Detection Lifecycle

  • Threat research: identify techniques to detect based on intelligence and risk
  • Rule development: write detection logic in a vendor-agnostic format (Sigma)
  • Testing: validate against known-good and known-bad data in a test environment
  • Peer review: have another engineer review the rule for logic, performance, and false positive potential
  • Deployment: push to production SIEM with appropriate severity and response tags
  • Tuning: monitor false positive rate and refine allowlists and thresholds
  • Retirement: decommission rules that are no longer relevant or effective

Sigma Rule Structure

ComponentPurposeExample
titleHuman-readable nameSuspicious PowerShell Encoded Command Execution
idUnique UUID for trackinga1b2c3d4-e5f6-7890-abcd-ef1234567890
statusDevelopment stagetest, experimental, stable
logsourceData source specificationcategory: process_creation, product: windows
detectionRule logic with conditionsselection, filter, condition combinations
levelAlert severitycritical, high, medium, low, informational
tagsMITRE ATT&CK mappingattack.execution, attack.t1059.001
falsepositivesExpected benign triggersAdministrative scripts, software deployment tools

Detection-as-Code Practices

Treat detection rules like software code. Store them in a Git repository with version control, branching, and pull request reviews. Automate testing using a CI/CD pipeline that validates syntax, runs against test data, and checks for performance impact before deployment. Maintain test cases for each rule: both expected-to-fire samples and expected-not-to-fire samples. Use infrastructure-as-code tools to deploy rules consistently across SIEM environments. This approach enables collaboration, auditability, and rollback when a rule causes problems in production.

ATT&CK Coverage Mapping

Map every detection rule to the specific MITRE ATT&CK technique and sub-technique it covers. Use the ATT&CK Navigator to visualize your coverage and identify gaps. Prioritize coverage for the techniques most commonly used against your industry, as identified by threat intelligence reports like Mandiant M-Trends and CrowdStrike Global Threat Report. Do not aim for 100% coverage immediately. Focus on the techniques that matter most and build outward. A few high-quality detections for critical techniques are worth more than hundreds of untested rules.

Quality Metrics

  • Track detection coverage as a percentage of prioritized ATT&CK techniques
  • Measure true positive rate per rule to identify your highest-value detections
  • Monitor false positive rate and time to tune for each new rule
  • Track mean time from rule creation to production deployment
  • Measure detection rule half-life: how long before a rule needs updating or retirement
  • Report on detection-driven incident discoveries to demonstrate program value

Frequently asked questions