Same rule. Same false positive. Nobody remembers who wrote it. Nobody dares delete it.
> 08:04. you log in.
> 47,832 open alerts +614 overnight
> overnight pages: 3 · 100% false positives
> 08:06. red team report: 14 days inside. zero alerts.
> 08:07. calendar: “URGENT” · 30 min · no agenda
Same rule. Same false positive. Nobody remembers who wrote it. Nobody dares delete it.
Paged. Escalated. False positive by 03:19. Sleep not recovered. Trust not recovered either.
Stopped matching when the log source changed in March. Nothing broke. Nothing fired. Nobody noticed.
industry estimate: ~5% of deployed detections actually work
A dead test VM: CRITICAL. The platform that makes the money: not covered. The SIEM doesn’t know which one pays your salary.
Test coverage: “worked in lab”. Version history: none. Rollback plan: coffee.
The slide says 87% MITRE coverage. The heatmap is green. Real threats don’t care.
The dashboard is finally green. So is the attacker’s path.
Every rule is written in the vendor’s query language. Leaving means rewriting 600 by hand. The vendor knows — the quote shows it.
Juniors aren’t allowed near detections. There’s no safe way to let them. So they close duplicates until they quit.
AI-powered auto-triage now enabled. The false positives are still generated. Now they’re closed faster, by something that also doesn’t know why they exist.
Nobody wrote down what it catches or what normal looks like. Just a name and a severity. The severity is wrong.
The rule stays. Changing it is archaeology. Deleting it is liability.
Every quarter adds rules. No quarter removes them. Nobody can say which ones still work, so nobody touches any of them.
Tuning request. Status: backlog. Priority: someday.
In a OneNote. Somewhere. Last updated three years ago by someone who left. Step 4 opens a console that no longer exists.
The incident is in Teams. The context is in a Jira ticket. The fix is in someone’s head. None of them link.
Hunting is a manual query and a wall of raw rows. Everyone agrees it matters. Nobody has the time.
New techniques drop weekly. Nobody triages the feed. The one that matters to your stack is in there somewhere.
The auditor asked if the detections work. We showed them a spreadsheet. Everyone nodded.
SIEM → next-gen SIEM → XDR → XDR with SOAR inside. The acronyms rotate. The queue is forever.
We bought the AI. It works. Look at the numbers.
mean time to triage
3s
99.9%
was 4h 12m
backlog
0
cleared
first time since 2019
analyst headcount
6
33%
efficiency gain
MITRE coverage
87%
unchanged
still never tested
detections fixed
0
—
not a tracked metric
not on the dashboard
Suspicious_PowerShell_v2_FINAL_old — auto-closed 3,411 times this quarter. Confidence: high. Every time. Still firing. Still nobody’s. The AI never asked why it exists; that isn’t what it was bought to do.#4821 — tuning request, 14 months open. Now assigned to nobody.The AI closed the alert.The broken rule is still running.
Tier 1 went offshore in Q1. Nearshore in Q3. Automated in Q4. The people who used to notice a rule had stopped working don’t work here anymore, and what replaced them was optimised to close alerts, not to ask whether the alert should have existed.
Ticket #4821 is assigned to nobody. Nobody is a role now.
Someone still has to decide what’s worth detecting, prove it works, and own it when it breaks. There’s no ticket type for that, no SLA on it, and no dashboard that goes green when you do it.
alerts auto-closed since you opened this page0
upstream problems fixed0
Forget the queue.
Your dev team ships with version control, tests, review, CI/CD, and one-click rollback. Your SOC edits regex in a production console and hits Save. Software engineering fixed this thirty years ago. Detection engineering never showed up to class.
Every change in version control, authored
The previous version of that rule is in someone's Downloads folder
Tests run on every commit
The test is production
CI tells you what breaks before you merge
No impact preview. Deploys are surprises.
Review required before merge
Edited live in the prod console. Reviewer: nobody.
Juniors merge code in week one. Tests and review make it safe.
Juniors close duplicates for two years. The rules are above their pay grade.
Staging environment
Production, but braver
Rollback is one command
Rollback is trying to remember what it said
When a service dies, you know in seconds
A rule dies silently. The first signal is a breach.
Dead code gets flagged and deleted
That rule has been running for four years. I guess.
Write once, build for every platform
Cross-SIEM is copy-paste regex and prayer
A CVE drops and the patch PR opens itself
A new technique drops. It stays in a PDF.
Priorities set by business impact
Priorities set by vendor default severity
Docs live in the repo, versioned
Docs live in a OneNote. Somewhere.
We need to set some rules.
The key words “MUST”, “MUST NOT” and “SHOULD” are to be interpreted per RFC 2119. (as old as your SIEM)
This needs to change.
We're not another AI that closes your alerts faster. We fix the detections generating them: weighted by the risk that's actually yours, written once in Sigma and compiled to whatever SIEM you run this year, tested before they ship, monitored so they never break silently, rolled back in one click.
We're CraftedSignal, and we're building the detection engineering control plane. Cool stuff.
Five questions. One loop.
p.s. while you read this, your queue grew by 41.