logo

The Detection Engineering Process

ID: c399915f-db7e-5f50-87f6-cc759f5338f8

STIX ID: report--c399915f-db7e-5f50-87f6-cc759f5338f8

Feed Name: Black Hills Infosec Blog

Date Published: 2024-11-18

Date Updated: 2026-04-27

Author: BHIS

...
...

This webcast transcript explains a detection engineering workflow that applies the scientific method to create high-quality security detections: start with a clear detection story, perform focused research, build and tune queries, backtest historical data, deploy canaries to validate ongoing operation, document using the ADS framework, onboard with suppression/throttling and a burn-in period, and continuously improve while managing risk; a PSExec plaintext-password detection is used as a concrete example, and the talk also covers practical topics like query language nuances, use of AI to assist documentation, and trade-offs in suppression and risk-based alerting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.