← All projects

Detection engineering · Case study

Sigma Detection Pack

Detection rules tested against both planted attacks and deliberate lookalikes.

At a glance

  1. 11 Sigma rules
  2. 6,038 synthetic events
  3. Positive + near-miss checks
  4. 12 passing tests

The problem

A detection can look plausible in YAML while missing the event it should catch or firing on routine activity. Conversion also depends on the target SIEM schema.

My role

Independent project. I wrote eleven Sigma rules, generated a synthetic event corpus, set expected matches and ran conversion and SQL behaviour tests in CI.

Key decision

Each rule has positive and near-miss examples. Tests compare returned event IDs with expected IDs; a missed positive or false positive fails the build.

Outcome

The corpus has 6,038 synthetic events, including 25 planted positives and 14 near-misses. Twelve tests passed in the documented run.

Limits

SQL behaviour is tested; generated SPL and supported KQL are conversion outputs, not validated in live Splunk or Sentinel. Five KQL conversions still require Sentinel parser mappings.

See the work

The repository contains the source, setup instructions and the evidence behind these results.

← Back to projectsGet in touch →