Why I started writing about detection engineering
Most of what I’ve learned about detection came from breaking things in production, reading logs at 2am, and asking analysts what actually helps them.
This blog is where I’ll write that down.
What you’ll find here
- Splunk searches and detection patterns that held up in real environments
- Lessons from onboarding log sources at scale
- How to run detections as a lifecycle, not a pile of rules
A detection nobody trusts is just noise with a name.
Thanks for reading.