Authors
Sri Sowmya Nemani, Independent Researcher, USA
Abstract
Security Operations Centers rely on detection engineering to convert telemetry from identity systems, endpoints, networks, and applications into actionable security alerts. However, many organizations struggle to align detections with adversary behavior, measure coverage, and maintain detection content at scale. This paper presents a practical ATT&CK-aligned detection engineering framework that combines telemetry assessment, field analysis, detection design, validation, tuning, and continuous monitoring. The framework is demonstrated through case studies covering password spraying, excessive DNS queries and failures, suspicious PowerShell activity, and Detection-as-Code workflows. Each case study maps detection logic to relevant MITRE ATT&CK techniques and discusses data sources, validation methods, tuning considerations, and operational lessons. The paper also compares the proposed approach with traditional indicator-based detection, standalone SIEM rule development, and ATT&CK mapping used only for reporting. The results show that ATT&CK-aligned detection engineering can improve visibility, reduce unmanaged detection gaps, and support scalable security monitoring across healthcare, financial services, e-commerce, education, government, and artificial intelligence environments.
Keywords
Detection Engineering, MITRE ATT&CK, Security Monitoring, SOC Operations, SIEM, Threat Detection, Cyber Defense, Security Analytics, Threat Hunting.