🧠
LANE 1 · CONTENT LAYER
Detection Engineering
Detection logic across multiple formats
Detection Formats
σ
Sigma Rules
Vendor-agnostic detection logic across all mapped MITRE ATT&CK tactics. Portable — translates into Wazuh XML and Splunk SPL.
Coverage spans Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, and C2. Each rule verified against repo — counts are script-generated.
↳ Sigma rules translated/adapted → Wazuh XML where applicable
⚙
Wazuh XML Rules
Custom rule blocks running natively in Wazuh Manager. Direct detection content — separate from AutoSOC runtime ingestion.
Includes both Sigma-translated rules and native custom rules targeting Wazuh-specific telemetry (syscheck, syscollector, vulnerability detection). All deployed to Wazuh Manager config.
›
Splunk SPL Detections
Parallel detection format. Splunk is an investigation lane — not the live ingestion backbone of AutoSOC.
Includes EventID 4688 process creation analysis, regex field extraction, and the independent threat hunt that correctly classified 375 Codex AI tool instances spawning pwsh.exe as tool behavior.
Supporting Content
📋 IR Playbooks
7-step structured format · linked to triage outputs · reproducible evidence capture
Portfolio Output
Published to GitHub + hawkinsops.com
Proof credibility
Portability demo
Detection depth
Format coverage
Verified counts
⚠ Architectural Note
Splunk is
not upstream of Wazuh. These are parallel detection content lanes — they share the same skill domain, not the same data path.