Urgent.News

What's breaking now, across thousands of outlets.

Tech

Detection content as code: reviewing a change the way you review software

Detection content as code: reviewing a change the way you review software The problem with editing rules in a console Detection rules written directly in a security platform have no review, no history, and no test. A change to a rule that suppresses a noisy alert is made because an analyst was paged at night, and the effect on coverage is discovered months later when the technique it caught…

Detecting threats in security systems often involves writing detection rules directly in a platform's console. However, this approach lacks essential features such as review, version history, and testing. When a rule change is made to reduce the number of false positives, it may go unnoticed for months until an incident reveals the problem. The solution lies in treating detection content as code, which introduces review, version control, and automated testing processes.

A recommended workflow includes storing detection rules in a plain text format within a repository. The platform should load the rules from this repository instead of the other way around. Sigma rules provide a portable intermediate representation that works across different security platforms. The first step in the review process is to verify that the rule accurately detects the intended threat described in its documentation and that it doesn't inadvertently start suppressing other meaningful threats.

Automated validation should be performed before merging any changes. This includes syntax checks to ensure the rule is properly formatted, as well as additional validation to confirm the rule behaves as intended. To comprehensively test a rule, it should be run against a dataset of recorded events. This helps verify that the rule correctly identifies known malicious samples while remaining silent on normal network traffic.

One common issue that leads to coverage erosion is the use of suppression mechanisms. Suppressions should be documented with specific information about the alert being suppressed, the source or account affected, the reason for the suppression, and an expiry date. By maintaining a suppression file with an expiry column, stale entries become visible, preventing unnoticed gaps in coverage.

When a rule is disabled entirely, it's crucial to record the covered threat technique and the decision-maker who accepted the resulting decrease in protection. This documentation helps turn an undocumented security gap into an intentional risk acceptance.

Thorough testing of detection rules is essential. The most effective method involves replaying actual recorded telemetry against the rule set and comparing the alerts generated before and after any changes. This approach can uncover problems like a renamed log field causing a rule to stop firing, which syntax validation alone cannot detect.

Additionally, maintaining a small set of known-bad samples with expected results allows for verifying that rules should be firing are functioning correctly. Rules that have never triggered in production should be considered untested, and their validation status should be monitored. Regularly tracking metrics such as rule count, technique coverage, and the number of active suppressions over time helps identify when detection capabilities are declining as the threat landscape evolves.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Day 16: Learning JavaScript DOM Manipulation — Create, Change & Delete Elements

My webdevelopment learning journey continues Today I learned about JavaScript DOM manipulation and how to create, modify, and delete HTML elements dynamically using JavaScript. 1.

  • document.getElementById() selects HTML elements by unique ID
  • document.createElement() creates new HTML elements dynamically
  • remove() method deletes elements from the webpage

Word-by-word captions with Python and ffmpeg, no CapCut watermark

Short-form video lives or dies on captions. CapCut and a dozen web tools will do the "word lights up as you say it" style for you, usually with a watermark or a free-minute limit.

  • Python script creates synchronized captions offline
  • Uses whisper with wordtimestamps for word boundaries
  • ffmpeg integrates captions without watermark

IDCF Cloud: Ransomware Disrupts Four Eastern Japan Zones; Customers Advised to Rebuild from Backups

1. Basic Information Report Title : [Third Report] Service Disruption Caused by Unauthorized Access to Part of Our Systems Source : IDC Frontier Date : 2026-10-08 Original Source : IDC Frontier…

  • Ransomware attack disrupts IDCF Cloud's Eastern Japan Region 1 on October 7, 2026
  • Four zones affected, 495 corporate and municipal clients impacted
  • Customers advised to rebuild systems from personal backups

Why Your Static Site’s lastmod Is a Lie (And How CI/CD Shallow Clones Secretly Hurt Your SEO)

If you build static websites, documentation hubs, or content platforms using Next.js, Astro, or 11ty, there is a very high probability that your sitemap.xml is quietly lying to Googlebot every single…

  • CI/CD shallow clones timestamp all files with current time, inflating last modified dates.
  • Search engines penalize sites with false timestamps, wasting crawl budget and slowing indexing.

Cross-Chain Bridge Risk Assessment: Deribit

Cross-Chain Bridge Risk Assessment: Deribit Target Protocol : Deribit (TVL: $3898.1M) Cross‑Chain Bridge Risk Assessment – Deribit TVL: ≈ $3.9 B (Ethereum + L2) Date: 9 Oct 2026 Prepared by: Senior…

More from Friday 9 October →