Blog

Notes on detection engineering, not generic monitoring advice.

Writing on rule maturity, detection content that survives contact with real data, and the difference between a rule that fires and one that adapts.

Engineering 10 min read

Per-tenant exclusions in a multi-tenant Sentinel estate

Generic rule logic, bespoke noise. Four patterns for handling customer-specific exclusions - saved functions, watchlists, and two flavours of CI/CD-injected exception block - and when to reach for each.

Read the post →
Framework 6 min read

The three-tier maturity framework, explained

What separates a T1 rule from a T3 rule, why most detection content never leaves T1, and how to grade what you've already got instead of guessing.

Read the post →
Practice 5 min read

Most detection rules just fire. Here's why.

Static conditions, no enrichment, and no owner. The three habits that keep detection content stuck, and what changes when a rule has to earn its alert.

Read the post →