Domain · nothing published yet

Detection & Response

Detection rules, triage, and the playbooks that turn an alert into a decision.

This is the area I've spent the most real hours in and the one with nothing on this page, because the work belongs to the banks I did it for. I'm rebuilding the same things in my own lab against traffic I generate myself.

At work: 55+ alert runbooks across SIEM and EDR at Sunflower Bank, a 35% cut in mean time to resolution, 10+ incident response playbooks at FirstBank, alert triage across 2,500+ endpoints in Splunk and CrowdStrike Falcon, and an ELK deployment at the McKeever Lab.
Roadmap

What's next

Listed before it exists so you can tell the difference.

ELK home lab

An Elastic stack taking in endpoint and network telemetry from a lab network I can make as noisy as I want.

Detection & Response Planned
Detection rule library

Sigma and KQL rules mapped to ATT&CK techniques, each with its false positive profile written down.

Detection & Response Planned
Attack and detection pairs

Run a technique, then write and tune the rule that catches it. Both halves published together.

Detection & Response Planned