I will build detection rules and tune your siem in wazuh, splunk or sentinel
Detection Engineer specializing in SIEM and Threat Hunting
About this Gig
Working detection engineer here. I sit in a live SOC and write the rules that catch real attacks. I'll write, test, and document detection rules for your SIEM: Wazuh, Splunk, Microsoft Sentinel, or Elastic. Tell me your log sources and what you're worried about, and I'll deliver rules that fire on attacker behavior, not noise. Every rule ships with a plain-English description of what it catches, a severity rating, false-positive notes so you know exactly when it triggers, and MITRE ATT&CK mapping at no extra charge. No access to your environment needed: describe your log sources or send sanitized samples, and I'll write against the schema. Not sure what you need? Message me first and I'll tell you honestly whether I can help.
Device:
Desktop
•
Laptop
•
Server
Operating system:
Windows
•
Linux

