{"slug":"sota-detection-engineering","title":"sota-detection-engineering","summary":"State-of-the-art detection engineering, SOC, threat hunting, and incident response (2026). Use when BUILDING detective controls or SOC capability — Sigma/YARA/Falco/Tetragon/Suricata rules, detection-as-code, MITRE ATT&CK coverage, SIEM detections, alert triage and SOAR, threat h","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-09T18:38:46.568025Z","repo":{"url":"https://github.com/martinholovsky/SOTA-skills","stars":23,"forks":2,"license":"CC-BY-4.0","updatedAt":"2026-09-27T16:35:16Z"},"bodyHtml":"<hr>\n<h2>name: sota-detection-engineering\ndescription: &gt;-\nState-of-the-art detection engineering, SOC, threat hunting, and incident\nresponse (2026). Use when BUILDING detective controls or SOC capability —\nSigma/YARA/Falco/Tetragon/Suricata rules, detection-as-code, MITRE ATT&amp;CK\ncoverage, SIEM detections, alert triage and SOAR, threat hunts,\nthreat-intel, deception, IR playbooks, or adversary emulation — AND when\nAUDITING detection &amp; IR posture (can we detect this? does this alert fire?).\nOwns DETECTIVE controls, SOC workflow, hunting, and IR (sota-observability\nowns the telemetry pipeline). Trigger keywords: detection engineering,\ndetection-as-code, Sigma, YARA, YARA-X, Falco, Tetragon, Suricata, SIEM,\nKQL, SPL, EQL, ATT&amp;CK, Pyramid of Pain, threat hunting, threat intel, TIP,\nSTIX, TAXII, IOC, IOA, TTP, SOC, alert fatigue, tuning, SOAR, runbook,\nincident response, IR playbook, NIST 800-61, PICERL, forensics, chain of\ncustody, purple team, honeypot, honeytoken, canary, OCSF, MTTD, false\npositive, Active Directory, Kerberoasting, DCSync, golden ticket, ADCS,\nRBCD.</h2>\n<h1>SOTA Detection Engineering, SOC &amp; Incident Response</h1>\n<h2>Purpose</h2>\n<p>Assume prevention fails. This skill builds and audits the layer that <em>notices</em>:\ndetective controls, the SOC that triages them, the hunts that find what alerts\nmiss, and the IR process that contains what hunts surface. One question defines\nsuccess:</p>\n<blockquote>\n<p><strong>When a real adversary acts inside your environment, does a high-fidelity\nsignal fire, reach a human (or automation) with the context to act, and drive\na bounded response — fast enough to matter?</strong></p>\n</blockquote>\n<p>Detection is engineering, not art. Detections are <strong>code</strong>: version-controlled,\npeer-reviewed, CI-tested, ATT&amp;CK-mapped, FP-budgeted, and retired when stale.\nThe dominant failure mode is not missing rules — it is <strong>alert fatigue</strong>: noise\nthat buries the one true positive. Optimize signal-to-noise relentlessly.</p>\n<p><strong>Ownership boundary.</strong> <code>sota-observability</code> owns the telemetry pipeline (logs,\nmetrics, traces, SLOs, log shipping, retention plumbing). This skill owns\nturning that telemetry into <em>security</em> detections, the SOC workflow, hunting,\nand IR. <code>sota-threat-modeling</code> owns design-time threat enumeration (STRIDE/\nATT&amp;CK/ATLAS catalogs); this skill owns catching those threats at runtime. If\nyou find yourself designing the logging schema, that's observability rules/01;\nif you find yourself enumerating threats on a DFD, that's threat-modeling.</p>\n<h2>BUILD mode</h2>\n<p>Run the detection lifecycle as a loop, not a one-shot. Hypothesis → build →\ntest → deploy → tune → retire. Workflow:</p>\n<ol>\n<li><strong>Start from a threat hypothesis, not a tool.</strong> Name the ATT&amp;CK technique or\nabuse case, the adversary behavior, and the telemetry that would witness it.\nUse the <strong>ADS framework</strong> (Palantir): goal, categorization (ATT&amp;CK), strategy\nabstract, technical context, blind spots/assumptions, false positives,\nvalidation, priority. Write this <em>before</em> the rule.</li>\n<li><strong>Confirm the log source exists first.</strong> You cannot detect what you do not\ncollect. Map the hypothesis to a concrete data source (EDR, cloud audit, K8s\naudit, network/flow, identity, app). If it's missing, the deliverable is a\n<em>logging gap</em>, not a rule. See rules/02.</li>\n<li><strong>Detect behavior over artifacts.</strong> Climb the <strong>Pyramid of Pain</strong>: prefer\nTTP/behavioral logic over brittle hashes/IPs/domains. IOC matches are cheap\nand disposable; TTP detections cost the adversary real money to evade.</li>\n<li><strong>Pick the right engine</strong> (rules/03): Sigma for log detections (vendor-\nagnostic, compiled to your SIEM), YARA-X for file/memory/malware, Suricata\nfor network, Falco/Tetragon for eBPF runtime/container/K8s, SIEM-native\n(KQL/SPL/EQL) for correlation the portable formats can't express.</li>\n<li><strong>Engineer for low FP from the start</strong> (rules/04): scope tightly, add\nallowlist context, require corroboration for noisy signals, set a severity\nhonestly. Every detection ships with a runbook (link to observability\nrules/04 alerting plumbing) and an owner.</li>\n<li><strong>Test before deploy.</strong> Validate with adversary emulation — Atomic Red Team\n(endpoint), Stratus Red Team (cloud), Caldera (campaigns). Confirm the\ndetection fires on the real technique and stays quiet on benign baselines.\nNo detection merges without a passing test. See rules/06.</li>\n<li><strong>Map coverage and find gaps.</strong> Track every detection against ATT&amp;CK with the\nNavigator. Coverage heatmaps reveal blind spots — feed them back to step 1.</li>\n<li><strong>Tune and retire.</strong> Review FP rates, suppress with <em>expiry</em> (never forever),\ndelete detections nobody trusts. A muted alert is worse than none.</li>\n</ol>\n<p>For hunting and deception, see rules/05; for IR, see rules/06.</p>\n<h2>AUDIT mode</h2>\n<p>Assess an existing detection/SOC/IR posture adversarially. Read rules/06 (IR &amp;\nvalidation) and rules/04 (SOC/triage) first. Sample real detections, real\nalerts, and real incidents — do not trust a coverage dashboard or a wiki\nrunbook that has never fired. The cardinal test: pick three ATT&amp;CK techniques\nrelevant to the environment and prove, end to end, that each would be caught.</p>\n<p><strong>Severity:</strong></p>\n<table>\n<thead>\n<tr>\n<th>Severity</th>\n<th>Meaning</th>\n<th>Examples</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Critical</td>\n<td>Blind to a primary attack path, or IR cannot execute</td>\n<td>No log source for the crown-jewel system; no EDR/cloud-audit/K8s-audit collection; no IR plan or no one on call; detections exist but nothing routes alerts to a human</td>\n</tr>\n<tr>\n<td>High</td>\n<td>Major coverage gap or SOC dysfunction</td>\n<td>Alert fatigue (analysts mute/ignore); detections never tested against the technique; IOC-only coverage of behaviors that need TTP logic; runbooks absent or stale; no ATT&amp;CK coverage map; retention too short for IR</td>\n</tr>\n<tr>\n<td>Medium</td>\n<td>Degraded fidelity or process gaps</td>\n<td>Detections with no owner/ADS doc; suppressions with no expiry; no deduplication/correlation; severity inflation; no purple-team/regression testing; TI not operationalized into detections</td>\n</tr>\n<tr>\n<td>Low</td>\n<td>Hygiene</td>\n<td>Detections not in version control; inconsistent naming; no FP metrics; Navigator layer stale; no blameless PIR template</td>\n</tr>\n<tr>\n<td>Info</td>\n<td>Observation / hardening opportunity</td>\n<td>Deception not deployed where it'd be high-value; coverage maturity below target; SOAR automation candidates</td>\n</tr>\n</tbody>\n</table>\n<p><strong>Finding format</strong> (one per finding):</p>\n<pre><code>file:line | rule | severity | effort (trivial/small/medium/large) | fix\n</code></pre>\n<p>Example:</p>\n<pre><code>detections/aws/iam.yml:14 | ioc-only-detection-of-ttp-behavior | High | medium |\n  GuardDuty-finding-name match is brittle; rewrite as CloudTrail behavioral\n  Sigma rule on CreateAccessKey+AttachUserPolicy by non-admin principal,\n  test with Stratus Red Team aws.persistence.iam-create-admin-access-key.\n</code></pre>\n<p>Conclude with the verdict: <strong>for the top 3 techniques in scope, is detection\nPRESENT / PARTIAL / ABSENT end-to-end</strong> (signal → alert → human → response),\nand the shortest path to closing the worst gap.</p>\n<h2>Rules index</h2>\n<table>\n<thead>\n<tr>\n<th>File</th>\n<th>Read this when...</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>rules/01-detection-engineering-discipline.md</code></td>\n<td>Running the detection lifecycle, writing ADS docs, doing detection-as-code (CI/peer review/regression), mapping coverage to ATT&amp;CK + Navigator, applying the Pyramid of Pain, picking maturity targets and metrics (coverage/precision/MTTD)</td>\n</tr>\n<tr>\n<td><code>rules/02-telemetry-siem-data-layer.md</code></td>\n<td>Deciding what to collect (the #1 gap), choosing SIEM/data-lake, normalizing with OCSF/ECS, sizing retention for IR/hunting, controlling volume/cost, assessing data quality</td>\n</tr>\n<tr>\n<td><code>rules/03-rule-languages-engines.md</code></td>\n<td>Choosing and writing detections in Sigma, YARA/YARA-X, Suricata, Falco, Tetragon, or SIEM-native (KQL/SPL/EQL); rule quality, specificity, FP-resistance, performance; good/bad examples</td>\n</tr>\n<tr>\n<td><code>rules/04-alerting-triage-soc-soar.md</code></td>\n<td>Fighting alert fatigue, tuning/suppression with expiry, severity assignment, enrichment, dedup/correlation, runbooks, SOAR + auto-containment guardrails, case management, FP lifecycle, SOC metrics</td>\n</tr>\n<tr>\n<td><code>rules/05-hunting-intel-deception.md</code></td>\n<td>Hypothesis-driven hunting + the hunt loop, IOC vs IOA/TTP hunting, threat-intel lifecycle + TIP, STIX 2.1/TAXII 2.1, diamond model/kill chain, deception (honeypots/honeytokens/canaries)</td>\n</tr>\n<tr>\n<td><code>rules/06-incident-response-validation.md</code></td>\n<td>Running IR (NIST SP 800-61r3 / CSF 2.0, PICERL), playbooks, severity classification, containment/eradication/recovery, forensic readiness + chain of custody, blameless PIR, tabletops; validating detections via Atomic Red Team/Caldera/Stratus, purple teaming, regression testing</td>\n</tr>\n<tr>\n<td><code>rules/07-ad-attack-detection.md</code></td>\n<td>Detecting on-prem Active Directory attacks: DC audit-policy telemetry and the events that matter (4768/4769/4770, 4662, 4624/4625, 5136, 8004, 4886/4887), Kerberoasting (RC4 TGS spikes), AS-REP roasting, DCSync (replication GUIDs on 4662), golden/silver tickets, DCShadow, ADCS abuse (ESC1), NTLM relay, password spraying, RBCD writes (5136); ATT&amp;CK mapping (T1558.x, T1003.006, T1207, T1649) + AD deception (honeytoken SPNs, canary objects). Hardening lives in sota-identity-access rules/07</td>\n</tr>\n</tbody>\n</table>\n<h2>Top 10 non-negotiables</h2>\n<ol>\n<li><strong>You can't detect what you don't collect.</strong> The #1 gap is telemetry, not\nrules. Audit log-source coverage against your attack paths before writing a\nsingle detection.</li>\n<li><strong>Detections are code.</strong> Version-controlled, peer-reviewed, CI-tested,\nATT&amp;CK-mapped, with an owner and an ADS doc. A detection that isn't tested\nisn't a detection — it's a hope.</li>\n<li><strong>Every detection is validated against the real technique.</strong> Atomic Red Team\n/ Stratus / Caldera proves it fires; a benign baseline proves it stays\nquiet. No merge without both.</li>\n<li><strong>Climb the Pyramid of Pain.</strong> Prefer TTP/behavioral logic over hashes/IPs/\ndomains. IOCs are a supplement and an enrichment, never the strategy.</li>\n<li><strong>Signal-to-noise is the product.</strong> Alert fatigue is the dominant SOC\nfailure. Tune aggressively, suppress with <em>expiry</em>, and treat a chronically\nignored alert as a Critical defect.</li>\n<li><strong>Every alert has a runbook and an owner.</strong> No actionable signal reaches a\nhuman without next steps. Wire alerting plumbing via sota-observability\nrules/04; you own the <em>security</em> content.</li>\n<li><strong>Map coverage to ATT&amp;CK and stare at the gaps.</strong> A Navigator heatmap that\nnobody updates is theater. Coverage drives the next hypothesis.</li>\n<li><strong>Behavior-detect, then enrich.</strong> Correlate, deduplicate, and decorate alerts\nwith asset/identity/TI context so triage is seconds, not minutes.</li>\n<li><strong>An IR plan that's never exercised is fiction.</strong> Tabletop it, keep contacts\nand authority-to-contain current, and run blameless post-incident reviews\nthat feed new detections.</li>\n<li><strong>Deception is the highest-fidelity signal you own.</strong> A touched honeytoken\nor honeypot has ~zero false positives. Deploy canaries in the paths\nattackers must traverse (see sota-secrets-management rules/04 honeytokens).</li>\n</ol>\n","files":[{"path":"rules/01-detection-engineering-discipline.md","sizeBytes":13983,"isText":true},{"path":"rules/02-telemetry-siem-data-layer.md","sizeBytes":25863,"isText":true},{"path":"rules/03-rule-languages-engines.md","sizeBytes":12133,"isText":true},{"path":"rules/04-alerting-triage-soc-soar.md","sizeBytes":10853,"isText":true},{"path":"rules/05-hunting-intel-deception.md","sizeBytes":9859,"isText":true},{"path":"rules/06-incident-response-validation.md","sizeBytes":12712,"isText":true},{"path":"rules/07-ad-attack-detection.md","sizeBytes":18545,"isText":true},{"path":"SKILL.md","sizeBytes":11070,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-27T20:58:03.198371Z","sha256":"0F1A14D9A357F2B236F04C0171D7AE6C2AB7EF3ED65221B810BA3DEF113B0D24","sizeBytes":51801},"review":null,"source":{"repositoryUrl":"https://github.com/martinholovsky/SOTA-skills","path":"skills/sota-detection-engineering","license":"CC-BY-4.0","commit":"c26df6ba7104740b44b56671937bf21659a70723","subtreeSha":"B7D8E7CC62FAAB84567C038CDEFA97853F302BA69F7EE42B385F09F0D569AB9B","lastSyncedAt":"2026-09-27T20:56:11.951045Z"},"reviewedAt":"2026-09-27T20:59:06.614423Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/martinholovsky/SOTA-skills/tree/main/skills/sota-detection-engineering"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install martinholovsky-sota-skills@llmmart"},{"target":"git","command":"git clone https://github.com/martinholovsky/SOTA-skills.git"}]}