Blue Team Detection Engineering
Problem: High false-positive rates in SIEM alerts. Approach: Tuned detection logic using ATT&CK mapping. Result: Lab-validated rules with documented methodology.
- Sigma-format detection rules (see GitHub repo)
- Documented tuning process and test cases
- ATT&CK technique coverage mapping