Detection engineering · Case study
Sigma Detection Pack
Detection rules tested against both planted attacks and deliberate lookalikes.
At a glance
- 11 Sigma rules
- 6,038 synthetic events
- Positive + near-miss checks
- 12 passing tests
The problem
A detection can look plausible in YAML while missing the event it should catch or firing on routine activity. Conversion also depends on the target SIEM schema.
My role
Independent project. I wrote eleven Sigma rules, generated a synthetic event corpus, set expected matches and ran conversion and SQL behaviour tests in CI.
Key decision
Each rule has positive and near-miss examples. Tests compare returned event IDs with expected IDs; a missed positive or false positive fails the build.
Outcome
The corpus has 6,038 synthetic events, including 25 planted positives and 14 near-misses. Twelve tests passed in the documented run.
Limits
SQL behaviour is tested; generated SPL and supported KQL are conversion outputs, not validated in live Splunk or Sentinel. Five KQL conversions still require Sentinel parser mappings.
See the work
The repository contains the source, setup instructions and the evidence behind these results.