The Tyne Bridge over the River Tyne The Gateshead Millennium Bridge, with Sage Gateshead and the Tyne Bridge behind Souter Lighthouse near South Shields Alnwick Castle in Northumberland Penshaw Monument overlooking Wearside

Most detection rules just fire.
Yours could adapt.

Independent, structured reviews and rewrites for your threat detection content - graded against a defined maturity framework, not a gut feeling.

Built by detection engineers who understand SOC challenges Reviewed and rebuilt to make the rules work for you and save hundreds of hours of analysis time. Not a generic consultancy pitch.
Services

Start with a verdict, or go straight to a rebuild.

Two ways in, depending on whether you need to know what's wrong first, or already know and just need it fixed.

Diagnosis

Detection Rule Maturity Review

Every rule you submit is assessed against a four-question decision tree and given a clear tier, with the reasoning shown and a specific recommendation for what would move it up.

  • T1 Fixed-condition logic — reliable, but static
  • T2 Enriched with maintained context
  • T3 Adaptive — detects deviation from baseline
From
£450
Enquire
Implementation

Detection Engineering Sprints

A bounded set of rules, rewritten using the same framework and pattern catalogue as the Review — handed over as working queries, tested against sample data, ready for your team to deploy.

  • 01 Scope agreed as a fixed rule list
  • 02 Built and tested against your sample data
  • 03 Delivered with a per-rule changelog
From
£1,000
Enquire
Process

Built to run asynchronously

No live access, no on-call element, no disruption to your team's day-to-day — everything is scoped upfront and delivered as a written report or a working rule set.

01

Scope

Rules, schema, or sample data sent over — scope agreed as a fixed list upfront.

02

Review

Assessed off-site, entirely asynchronously, against the tiered framework.

03

Deliver

Written report or rewritten rules, with reasoning and a changelog.

04

Walk through

One follow-up call to go through the findings and next steps.

About

Detection engineering, not generic monitoring advice.

I'm a SOC Team Lead and detection engineer with hands-on experience across Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, and Elastic Security — working detections, not slideware.

I maintain a public threat hunt library and contribute to the wider detection engineering community.

Core tooling
Microsoft Sentinel (KQL), Defender XDR, CrowdStrike Falcon, Elastic Security
Published work
SentinelHunt — a public threat hunt library, at rustedroberts.github.io
Community
Contributor to the Discover Detections project
Get in touch

Tell me what's not catching what it should.

Send over a bit of context — your stack, roughly how many rules, and what you're trying to get out of it — and I'll reply with next steps.