Skip to content

Publish a complete documentation-first detection pack example #54

Description

@egrexsec

Objective

Create a small but complete detection pack that demonstrates DetLab-DAC's documentation-first workflow end to end.

Rationale

Recruiters, detection engineers, and contributors need one polished example that proves the platform is more than a UI shell. A complete pack should show canonical briefs, multiple implementations, telemetry assumptions, triage, validation notes, and review-ready markdown.

Scope

  • Pick one focused behavior chain such as suspicious PowerShell execution to credential-access follow-on.
  • Include 3-5 related detection briefs.
  • Provide Sigma, SPL, KQL, EQL, and ES|QL implementations where reasonable.
  • Include ATT&CK mapping, telemetry assumptions, false positives, triage steps, and validation notes.
  • Link the pack from the README.

Acceptance criteria

  • Pack renders in the web workbench.
  • Each detection has complete documentation sections.
  • Cross-links or related detections show a coherent analyst workflow.
  • No claim implies production validation beyond what is actually documented.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions