The Tyne Bridge over the River Tyne The Gateshead Millennium Bridge, with Sage Gateshead and the Tyne Bridge behind Souter Lighthouse near South Shields Alnwick Castle in Northumberland Penshaw Monument overlooking Wearside

Most detection rules just fire.
Yours could adapt.

Independent, structured reviews and rewrites for your threat detection content - graded against a defined maturity framework, not a gut feeling.

Built by a detection engineer who understands the challenges of modern threat detection. Reviewed and rebuilt to make the rules work for you and save hundreds of hours of analysis time. Not a generic consultancy pitch.
Services

Start with a verdict, go straight to a rebuild, or get ongoing support.

Whether you need to know what's wrong first, already know and just need it fixed, or need the responsiblilty of maintaining your detection content handled by someone else.

Diagnosis

Detection Rule Maturity Review

Every rule in scope is assessed against a defined maturity framework and given a clear tier, with the reasoning shown and a specific recommendation for what would improve it.

  • T1 Fixed-condition logic - reliable, but static
  • T2 Enriched with maintained context to promote automation capability
  • T3 Adaptive - detects deviation from baseline
From
£450
Enquire
Implementation

Detection Engineering Sprints

A bounded set of rules, rewritten using the same framework and pattern catalogue as the Review - handed over as working queries, tested against sample data, ready for your team to deploy.

  • 01 Scope agreed as a fixed rule list
  • 02 Built and tested against your sample data
  • 03 Delivered with a per-rule changelog
From
£1,000
Enquire
Retainer

Detection Engineering Partner

For MSPs, MSSPs, and internal SOCs that need detection content built and maintained on an ongoing basis, not just once. I plug in as your external content developer, working a rolling backlog rather than a single fixed batch.

  • 01 Rolling backlog, prioritised together each month
  • 02 New and rewritten rules delivered on a set cadence
  • 03 Maturity tracked over time, not assessed once and left
From
£650/mo
Enquire
The framework

Every tier above comes from the same three-tier model.

Atomic, contextual, behavioural - what separates them, why complexity isn't maturity, and four questions you can run against ten of your own rules this week.

Read the framework
Process

Built to run asynchronously

No disruption to your team's day-to-day - everything is scoped upfront and delivered as a written report or a working rule set.

01

Scope

Rules, schema, or sample data sent over - scope agreed as a fixed list upfront.

02

Review

Assessed off-site, entirely asynchronously, against the tiered framework.

03

Deliver

Written report or rewritten rules, with reasoning and a changelog.

04

Walk through

One follow-up call to go through the findings and next steps.

About

Detection engineering, not generic monitoring advice.

I'm an experienced SOC Team Lead and detection engineer with hands-on experience across multiple sectors - creating actionable detections that provide full context, not simply fill a coverage gap.

Core tooling
Microsoft Sentinel (KQL), Defender XDR, CrowdStrike Falcon, Elastic Security
Published work
SentinelHunt - a public threat hunt library, at rustedroberts.github.io
Community
Contributor to the Detections.ai community detections.ai
Get in touch

Tell me what's not catching what it should or where your detection content is drowning you in alerts

Send over a bit of context - your stack, roughly how many rules, and what you're trying to get out of it - and I'll reply with next steps.

Alternatively, if you don't know where to start, contact me and we can have a chat about your challenges. No obligation - just a conversation.