TutorialDetection Engineering
Updated 1 month ago
Tutorial: tune your first SIEM correlation rule
Hands-on tutorial. Take a noisy detection rule, instrument it, and tune it down to an alert volume your team will actually action.
OSCI Editorial
Collaboratively written by mentors and contributors.
You will need: a SIEM with at least one week of telemetry, one detection rule firing at least 20 times per day, and a willingness to read your own logs.
Step one: instrument. Step two: decompose the rule into its base predicate and its context. Step three: enrich. Step four: throttle. We walk each step with concrete examples.