Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “detection engineering”
3 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysis
Normalize cloud security logs with OCSF before writing detections
OCSF puts CloudTrail, Azure Activity Log and Google audit records into the same API Activity fields. Detections still depend on the mapping, the schema version and provider semantics that normalization does not erase.
Detection & response · Open Cybersecurity Schema Framework / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskTesting Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Detection & response · SigmaHQ · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security Desk