Skip to content
fernet.consultores

Splunk Cloud

Detection Engineering.

Detection use cases that are written, mapped to MITRE ATT&CK, tested and maintained as code.

The problem we solve.

Many detection rules are written once and never revisited: nobody knows which technique they cover, whether they still work, or how many false positives they generate. Real coverage is an unknown.

What’s included.

  • Coverage map against MITRE ATT&CK
  • Design and writing of detections
  • Testing with controlled simulations
  • False-positive tuning
  • Detections-as-code lifecycle

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We write detections as code, with their description, ATT&CK mapping and tests, and deploy them in a controlled way.

We reproduce each technique in a controlled environment and confirm the alert fires with context and does not trigger on legitimate activity.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • SPL and tstats
  • MITRE ATT&CK
  • Enterprise Security Content Update
  • Atomic Red Team
  • Splunk Attack Range
  • contentctl

What part of the attack are you actually seeing?

These are the fourteen MITRE ATT&CK tactics for enterprise environments, in the order an attack typically progresses. Tick the ones you currently detect with at least one tested use case and see where the gaps are.

0 of 14 tactics

Start by ticking the tactics you already detect. You'll see an example use case for each one.

Use cases.

Know your coverage

Find out which parts of an attack you'd see today and which you wouldn't.

Reduce false positives

Make every alert worth an analyst's attention.

New threats

Add detections as the threat landscape changes.

Benefits for your organisation.

  • Measurable, explainable coverage
  • Detections known to work
  • Less noise for the SOC
  • Content your team can maintain

Deliverables.

  • ATT&CK coverage matrix
  • Detection repository
  • Test results
  • Maintenance procedure

Frequently asked questions.

How do you know a detection works?

We test it: we reproduce the technique in a controlled environment and check that the alert fires with the necessary context and doesn't trigger on legitimate activity.

What does detections-as-code mean?

Each detection lives in a repository with its description, its ATT&CK mapping and its tests, and is deployed in a controlled way.

Do you work without Enterprise Security?

Yes. Detections can be built on Splunk Cloud; Enterprise Security adds incident management and risk-based alerting.

Shall we talk about Detection Engineering?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service