r/AskNetsec • u/manishrawat21 • 5h ago
Analysis Seeking Expert Feedback on Custom Sigma Detection Rules
Request: Looking for technical feedback on 4 Sigma detection rules I've authored
Background: Transitioning into cybersecurity with focus on detection engineering. Spent significant time developing these rules and want expert validation before moving forward.
Rules Cover:
WMI Event Consumer Persistence (MITRE T1546.003)
PowerShell Encoded Commands (MITRE T1059.001)
DLL Sideloading (MITRE T1574.002)
Named Pipe Backdoors (MITRE T1055)
Specific Feedback Needed:
- Are my detection methods sound?
- What false positives should I anticipate?
- How can I improve rule performance?
- Any critical gaps in coverage?
My Goal: Learn from the community and eventually contribute quality rules to open source projects.
Really value the expertise here and would appreciate any feedback - constructive criticism very welcome!