SOC Headaches Queue

queue · filter: ALL · sort: oldest unacknowledged · showing 1–20 of 47,832

criticalSuspicious_PowerShell_v2_FINAL_old · firing 14× today · assignee: none

Same rule. Same false positive. Nobody remembers who wrote it. Nobody dares delete it.

critical03:12 AM · escalated · on-call: you

Paged. Escalated. False positive by 03:19. Sleep not recovered. Trust not recovered either.

highsilent for 212 days · last fired: March

Stopped matching when the log source changed in March. Nothing broke. Nothing fired. Nobody noticed.

industry estimate: ~5% of deployed detections actually work

criticalseverity source: vendor default

A dead test VM: CRITICAL. The platform that makes the money: not covered. The SIEM doesn’t know which one pays your salary.

highdeployed via: pasting into prod console

Test coverage: “worked in lab”. Version history: none. Rollback plan: coffee.

inforecurring: monthly, before board meeting

The slide says 87% MITRE coverage. The heatmap is green. Real threats don’t care.

lowthreshold raised again · fourth time this quarter

The dashboard is finally green. So is the attacker’s path.

highrenewal quote: +40% · negotiating leverage: none

Every rule is written in the vendor’s query language. Leaving means rewriting 600 by hand. The vendor knows — the quote shows it.

mediumtier 1 · time-to-touching-a-rule: 2 years

Juniors aren’t allowed near detections. There’s no safe way to let them. So they close duplicates until they quit.

newvia: vendor webinar

AI-powered auto-triage now enabled. The false positives are still generated. Now they’re closed faster, by something that also doesn’t know why they exist.

highdescription: (empty) · expected behavior: undocumented

Nobody wrote down what it catches or what normal looks like. Just a name and a severity. The severity is wrong.

mediumauthor: left the company two years ago

The rule stays. Changing it is archaeology. Deleting it is liability.

mediumrule count: 1,412 · retired this year: 0

Every quarter adds rules. No quarter removes them. Nobody can say which ones still work, so nobody touches any of them.

mediumticket #4821 · opened 14 months ago

Tuning request. Status: backlog. Priority: someday.

mediumrunbook: SOC_Procedures_FINAL_(copy)(2).one

In a OneNote. Somewhere. Last updated three years ago by someone who left. Step 4 opens a console that no longer exists.

lowescalated via: Teams thread · 47 replies

The incident is in Teams. The context is in a Jira ticket. The fix is in someone’s head. None of them link.

mediumthreat hunt · status: skipped, again

Hunting is a manual query and a wall of raw rows. Everyone agrees it matters. Nobody has the time.

infothreat feed · unread: 212 advisories

New techniques drop weekly. Nobody triages the feed. The one that matters to your stack is in there somewhere.

infoaudit season

The auditor asked if the detections work. We showed them a spreadsheet. Everyone nodded.

infoplatform: rebranded again

SIEM → next-gen SIEM → XDR → XDR with SOAR inside. The acronyms rotate. The queue is forever.

SOC performance analytics · Q4 board pack · auto-generated, do not edit

Everything is green now.

We bought the AI. It works. Look at the numbers.

mean time to triage

3s

99.9%

was 4h 12m

backlog

0

cleared

first time since 2019

analyst headcount

6

33%

efficiency gain

MITRE coverage

87%

unchanged

still never tested

detections fixed

0

not a tracked metric

not on the dashboard

  • Suspicious_PowerShell_v2_FINAL_old — auto-closed 3,411 times this quarter. Confidence: high. Every time. Still firing. Still nobody’s. The AI never asked why it exists; that isn’t what it was bought to do.
  • The rule that stopped matching in March — silent 212 days, unchanged. Nothing to auto-close, nothing to notice. A dashboard can’t show you the alert that didn’t fire.
  • Ticket #4821 — tuning request, 14 months open. Now assigned to nobody.

The AI closed the alert.The broken rule is still running.

Tier 1 went offshore in Q1. Nearshore in Q3. Automated in Q4. The people who used to notice a rule had stopped working don’t work here anymore, and what replaced them was optimised to close alerts, not to ask whether the alert should have existed.

Ticket #4821 is assigned to nobody. Nobody is a role now.

Someone still has to decide what’s worth detecting, prove it works, and own it when it breaks. There’s no ticket type for that, no SLA on it, and no dashboard that goes green when you do it.

alerts auto-closed since you opened this page0

upstream problems fixed0

Forget the queue.

It's 2026. You're detecting like it's 1997.

Your dev team ships with version control, tests, review, CI/CD, and one-click rollback. Your SOC edits regex in a production console and hits Save. Software engineering fixed this thirty years ago. Detection engineering never showed up to class.

Every change in version control, authored

The previous version of that rule is in someone's Downloads folder

Tests run on every commit

The test is production

CI tells you what breaks before you merge

No impact preview. Deploys are surprises.

Review required before merge

Edited live in the prod console. Reviewer: nobody.

Juniors merge code in week one. Tests and review make it safe.

Juniors close duplicates for two years. The rules are above their pay grade.

Staging environment

Production, but braver

Rollback is one command

Rollback is trying to remember what it said

When a service dies, you know in seconds

A rule dies silently. The first signal is a breach.

Dead code gets flagged and deleted

That rule has been running for four years. I guess.

Write once, build for every platform

Cross-SIEM is copy-paste regex and prayer

A CVE drops and the patch PR opens itself

A new technique drops. It stays in a PDF.

Priorities set by business impact

Priorities set by vendor default severity

Docs live in the repo, versioned

Docs live in a OneNote. Somewhere.

We need to set some rules.

The SoC Manifesto

The key words “MUST”, “MUST NOT” and “SHOULD” are to be interpreted per RFC 2119. (as old as your SIEM)

  1. Every alert MUST be worth a human’s attention.An alert nobody reads is a lie.
  2. Noise MUST go down over time, not up.Volume is not vigilance. Auto-closing garbage faster is still garbage.
  3. “Critical” MUST be rare.When everything is critical, nothing is.
  4. Severity MUST come from what the business loses.The vendor default doesn’t know what pays your salary.
  5. Detection MUST start from risk, not a rule pack.If you can’t say what it protects, you’re collecting logs with extra steps.
  6. Management MUST NOT move the metric to go green.Changing the measurement is not reducing the risk. A green heatmap protects the slide.
  7. Every detection MUST be tested before it ships.Untested detections are guesses. Guesses in production are liabilities.
  8. Detections MUST live in version control.“The old version is in my Downloads folder” is not version control.
  9. Detection MUST have one source of truth.Rules scattered across five consoles aren’t a portfolio. They’re drift with a login page.
  10. Tuning MUST preserve the detection’s objective.Tuning until it stops firing is not tuning. It’s deleting the rule in slow motion.
  11. Rules MUST be a portfolio, not a pile.Every rule needs an owner, a test, and a reason to exist. Delete the rest.
  12. A rule that goes silent MUST page someone.Otherwise your SIEM is a diary with a license fee.
  13. Intel MUST become detections in days, not weeks.A technique that sits in a PDF for a month is history, not intelligence.
  14. AI MUST accelerate the engineering, not the closing.Closing 47,832 alerts faster is a faster way to miss the one that mattered.
  15. Tier 1 MUST NOT be a life sentence.Closing duplicates for two years is not a career path. It’s a symptom.
  16. Analysts MUST hunt.You were hired to hunt threats, not click around like a monkey.

This needs to change.

queue · filter: TRUE_POSITIVE (1) · sort: signal

true positiveconfidence: high · source: verified

BUT. We're building the fix.

We're not another AI that closes your alerts faster. We fix the detections generating them: weighted by the risk that's actually yours, written once in Sigma and compiled to whatever SIEM you run this year, tested before they ship, monitored so they never break silently, rolled back in one click.

We're CraftedSignal, and we're building the detection engineering control plane. Cool stuff.

Five questions. One loop.

  • 01riskwhat should we be defending?
  • 02threatwhat attacks will happen?
  • 03huntis it already happening?
  • 04monitorare we being protected?
  • 05verifyare we 100% sure?
Fix your SOC

p.s. while you read this, your queue grew by 41.

triage score 0 risk reduced: 0%