KQL validation harness notes
Notes on building a deterministic KQL validation harness for schema checks and regression detection.
2025-12-01
Practical notes and experiments from detection engineering and SOC architecture work.
Notes on building a deterministic KQL validation harness for schema checks and regression detection.
2025-12-01
Experimental mapping approach for Sigma rules to Sentinel-compatible KQL with validation checkpoints.
2025-11-21
Lab observations on repeatable test execution patterns for validating detection behavior and noise profiles.
2025-11-10
Practical comparison of baseline-driven and threshold-driven detection strategies across evolving environments.
2025-10-28
Concept notes for detecting schema drift and missing fields before downstream analytics or detections fail.
2025-10-02
Triage framework notes for evidence prioritization, enrichment, and escalation quality control.
2025-09-15