Independent, structured reviews and rewrites for your threat detection content - graded against a defined maturity framework, not a gut feeling.
Whether you need to know what's wrong first, already know and just need it fixed, or need the responsiblilty of maintaining your detection content handled by someone else.
Every rule in scope is assessed against a defined maturity framework and given a clear tier, with the reasoning shown and a specific recommendation for what would improve it.
A bounded set of rules, rewritten using the same framework and pattern catalogue as the Review - handed over as working queries, tested against sample data, ready for your team to deploy.
For MSPs, MSSPs, and internal SOCs that need detection content built and maintained on an ongoing basis, not just once. I plug in as your external content developer, working a rolling backlog rather than a single fixed batch.
Atomic, contextual, behavioural - what separates them, why complexity isn't maturity, and four questions you can run against ten of your own rules this week.
No disruption to your team's day-to-day - everything is scoped upfront and delivered as a written report or a working rule set.
Rules, schema, or sample data sent over - scope agreed as a fixed list upfront.
Assessed off-site, entirely asynchronously, against the tiered framework.
Written report or rewritten rules, with reasoning and a changelog.
One follow-up call to go through the findings and next steps.
I'm an experienced SOC Team Lead and detection engineer with hands-on experience across multiple sectors - creating actionable detections that provide full context, not simply fill a coverage gap.
Send over a bit of context - your stack, roughly how many rules, and what you're trying to get out of it - and I'll reply with next steps.
Alternatively, if you don't know where to start, contact me and we can have a chat about your challenges. No obligation - just a conversation.