Independent, structured reviews and rewrites for your threat detection content - graded against a defined maturity framework, not a gut feeling.
Two ways in, depending on whether you need to know what's wrong first, or already know and just need it fixed.
Every rule you submit is assessed against a four-question decision tree and given a clear tier, with the reasoning shown and a specific recommendation for what would move it up.
A bounded set of rules, rewritten using the same framework and pattern catalogue as the Review — handed over as working queries, tested against sample data, ready for your team to deploy.
No live access, no on-call element, no disruption to your team's day-to-day — everything is scoped upfront and delivered as a written report or a working rule set.
Rules, schema, or sample data sent over — scope agreed as a fixed list upfront.
Assessed off-site, entirely asynchronously, against the tiered framework.
Written report or rewritten rules, with reasoning and a changelog.
One follow-up call to go through the findings and next steps.
I'm a SOC Team Lead and detection engineer with hands-on experience across Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, and Elastic Security — working detections, not slideware.
I maintain a public threat hunt library and contribute to the wider detection engineering community.
Send over a bit of context — your stack, roughly how many rules, and what you're trying to get out of it — and I'll reply with next steps.