Knowledge Base

Detection Engineering Lifecycle

Manage detection objectives, telemetry, testing, ownership, and retirement without treating alerts as proof.

Lifecycle

A detection specification should name its threat hypothesis, required telemetry, logic, expected signal, severity, priority, confidence, owner, dependencies, testing evidence, and review date. Behavior-based logic and indicator-based logic have different assumptions. A detection rule is not proof of compromise, and no alert does not prove no malicious activity occurred.

Review checklist

Fictional example

A suspicious-login rule combines identity and device context. A review finds one source lacks a stable device field, so the team scopes the rule, records the gap, and avoids a broad compromise claim.

Related: Detection Readiness, Alert Quality, Detection Rule Review.