Skip to content
All systems nominalMITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
Purple team

Detection engineering.

Every red-team finding becomes a detection that survives the next assessment. We sit with your blue team, replay the technique, and ship the rule that would have caught us.

Book engagementSigma · KQL · YARA · ATT&CK coverage map included
// 01  —  What it is

Red finding. Validated rule. No gap left open.

Detection engineering bridges the red team and the SOC. We don't just hand over a finding — we replay the technique, instrument every log source, and write the rule that would have stopped the chain before it reached your objective.

Every detection is tuned against real replay data. False-positive rate is tested before delivery. The runbook goes with the rule so your analyst knows exactly what to do with an alert at 2 AM.

  • Shoulder-to-shoulder with your blue team and SIEM engineers
  • Detection-first replay — every event observable before rule authoring
  • Sigma, KQL, YARA output in your stack's native format
  • ATT&CK coverage delta shown before and after
  1. 01Finding triageRed team output reviewed, ranked, and queued for detection development.Input
  2. 02Controlled replayWe re-execute the technique in a safe environment with full telemetry on.Active
  3. 03Telemetry mappingEvery log source touched is inventoried. Gaps in coverage identified.Analysis
  4. 04Rule writing & testingSigma / KQL / YARA authored and validated against replay data.Engineering
  5. 05Coverage reportATT&CK matrix updated. Runbook and SOC playbook delivered.Output
  • Initial access
  • Execution
  • Persistence
  • Privilege escalation
  • Defence evasion
  • Credential access
  • Discovery
  • Lateral movement
  • Collection
  • Command & control
  • Exfiltration
  • Impact
// 02  —  How we run it

Five stages from finding to detection.

  1. Engagement scoping

    We review your existing detection stack, log sources, and the red team findings or TTPs you want covered.

  2. Controlled attack replay

    Each technique is re-executed in an isolated environment with full telemetry collection active across every log source.

  3. Log & telemetry analysis

    We walk through every event generated and map it back to an observable. Coverage gaps become explicit line items.

  4. Rule development

    Sigma, KQL, YARA — whichever format your SIEM/EDR stack consumes. Tuned to minimize false positives without hiding the signal.

  5. Validation & handoff

    Rules are tested against live (isolated) replay before delivery. Runbook and playbook go with every detection.

// 03  —  What you get

Rules that fire. Runbooks that work.

// next step

Turn your next red team finding into a detection.

Scoping call · fixed-price · ATT&CK coverage map delivered.

Schedule a scoping call