The discipline that separates rule writers from detection engineers
Field Notes

Rule Writing to Risk Reduction

The discipline that separates a rule writer from a detection engineer — and why raw severity is not the same number as real priority.