Dead on Arrival: The Detection That Physically Can Not Fire - Detection Engineer
Details
Dead on Arrival: The Detections That Physically Cannot Fire / Detection Engineering
💫Grab your ticket and secure your spot:
Registration Link for Full day Event
** 🦄 This is low cost and budget friendly and paid... **
A detection rule can sit in your repo, pass CI, and glow green on your ATT&CK coverage map while being physically incapable of firing. Not misconfigured. Incapable. It reads a log field that nobody collects, so no event will ever match it, and nothing on your dashboard tells you.
This is one of the most common silent failures in a real detection stack, and it is the one nobody owns. Coverage maps measure whether a rule was written, not whether it can fire. SIEM rule-health checks confirm a rule ran without error, and a rule running over data that never contains the field it needs runs without error too. It just runs over nothing. The gap between "quiet" and "dead" is invisible.
I built a small, read-only checker that closes that gap deterministically. It takes your Sigma rules, resolves the fields each one needs through your normal pySigma pipeline, and asks your SIEM's schema whether those fields are actually present, using metadata APIs like Elastic field_caps.
There is no matching, no scoring, no model: a field exists or it does not, so a rule can fire or it cannot. The verdict is FIREABLE or DEAD-ON-ARRIVAL with the exact missing field.
💫Grab your ticket and secure your spot:
Registration Link - Full Day Event
This is low cost and budget friendly events.
