Writing detections that do not page you at 3am
A detection that fires forty times a night is worse than no detection, because it trains the team to ignore it. How to write one that survives contact with production.
Every SOC has a rule that everyone mutes. It fires constantly, nobody has tuned it, and one day it will fire for a real intrusion and get dismissed with the rest.
A detection needs three things before it goes live. A hypothesis: what specific attacker behaviour does this catch? A baseline: how often does this happen normally, measured over at least two weeks of real telemetry? And a response: what does the analyst actually do when it fires?
If you cannot answer the third question, you have written an alert, not a detection. Alerts without a defined response are how alert fatigue starts.
The practical test we use in the lab: run the rule against thirty days of historical data before enabling it. If it would have fired more than about five times, it is not ready. Tighten the hypothesis, not the threshold.