Tag: Detection Engineering
October 28, 2025
/ Masterclass
đź”§ Detection-as-Code: What It Really Means
Masterclass Series – Part 2 đź§ TL;DR: It’s Not Just “Put Your Rules in Git” “Detection-as-Code” sounds like a trendy…
October 23, 2025
/ Insights
The Cost of Crying Wolf: Why False Positives Are Killing Your SOC
Introduction It’s not the alerts you miss that break a SOC — it’s the thousands you never should have seen…
October 16, 2025
/ Case Study
When CIM Mapping Goes Sideways: Lessons from a Broken Detection
🔎 Introduction Everything looked good on paper:âś… The detection rule was written.âś… The sourcetype was CIM-mapped.âś… The data model was…
October 14, 2025
/ Masterclass
đź§ Macro-Driven Rule Logic – Splunk Masterclass 1/5
đź‘‹ Welcome to the LogSmith Splunk Masterclass This series is for detection engineers, Splunk admins, and SOC architects who want…
October 6, 2025
/ Case Study
Case Study : Taming the 21,000-Alert-a-Day SIEM
How I helped restore clarity and control to a chaotic Splunk ES environment