Why I started writing about detection engineering
After 13 years in SIEM and SOC work, I'm putting my notes somewhere public.
Tuning use cases without losing coverage
A starter post showing headings, lists, and a Splunk search. Replace it with your own.