Objective
Create a small but complete detection pack that demonstrates DetLab-DAC's documentation-first workflow end to end.
Rationale
Recruiters, detection engineers, and contributors need one polished example that proves the platform is more than a UI shell. A complete pack should show canonical briefs, multiple implementations, telemetry assumptions, triage, validation notes, and review-ready markdown.
Scope
- Pick one focused behavior chain such as suspicious PowerShell execution to credential-access follow-on.
- Include 3-5 related detection briefs.
- Provide Sigma, SPL, KQL, EQL, and ES|QL implementations where reasonable.
- Include ATT&CK mapping, telemetry assumptions, false positives, triage steps, and validation notes.
- Link the pack from the README.
Acceptance criteria
- Pack renders in the web workbench.
- Each detection has complete documentation sections.
- Cross-links or related detections show a coherent analyst workflow.
- No claim implies production validation beyond what is actually documented.
Objective
Create a small but complete detection pack that demonstrates DetLab-DAC's documentation-first workflow end to end.
Rationale
Recruiters, detection engineers, and contributors need one polished example that proves the platform is more than a UI shell. A complete pack should show canonical briefs, multiple implementations, telemetry assumptions, triage, validation notes, and review-ready markdown.
Scope
Acceptance criteria