Detection

Detection as Code

Detection as Code manages detection rules like software: versioned, tested, reviewed and deployed automatically.

Detection as Code means that detection rules are developed, versioned, tested, and deployed like software. The rules reside in a repository and follow a defined process.

How it works

Each rule is a file, for example in Sigma format or the SIEM's native language. Changes are submitted as a pull request and reviewed by a second person. Automated tests check syntax, expected matches, and known benign cases. Only then is the rule deployed to the platform via a pipeline. Every version remains traceable, and changes can be rolled back.

A practical example: an analyst adjusts a rule because it generates too many false positives. The test shows the adjustment no longer detects a known attack from a previous Case. The change is improved before it goes into operation. Without this test, the gap would only have been noticed during a real attack.

What to look out for

  • Create test data for each rule that triggers a valid detection.
  • Record metadata: purpose, ATT&CK technique, severity, and the responsible person.
  • Roll out changes gradually, first without alerts, then into production.
  • Measure the number of true and false positives for each rule.

Advantages

Detection as Code makes the quality of the rules verifiable. Changes are documented, which simplifies audits. Teams can reuse rules between different customers or environments. Rules can also be more easily transferred to another platform.

Typical mistakes

Often, only the storage location is changed without introducing tests and reviews. The benefit then remains limited. A second mistake is changing rules directly in the console. The repository and the live environment then diverge.

Relevance for the SOC

A SOC with many customers needs standardised and tested rules. Detection as Code enables rolling out improvements quickly for all clients while maintaining customer-specific exceptions.

How we implement it

We manage our detection rules as code: versioned, tested and tuned to your environment. Each rule is mapped to ATT&CK techniques. We are happy to discuss architecture questions as part of our Security Consulting.

How ANOMAL implements this