← Calyvex Lab
PrototypePlanned prototype

Detection Content Library

A structured prototype for storing detection logic together with telemetry requirements, validation steps and tuning notes.

SigmaDetection EngineeringSIEMGitHub

Prototype objective

The library will explore a version-controlled structure for detection content that includes more than a query or rule file.

Proposed record structure

  • Behavioral objective.
  • Required telemetry.
  • Detection logic.
  • ATT&CK mapping where appropriate.
  • Controlled validation procedure.
  • Expected evidence.
  • False-positive conditions.
  • Tuning and revision history.

Current status

The prototype is planned. Initial content will be added after controlled lab validation.

Build with Calyvex

Need a practical security solution?

Tell us what you are trying to detect, understand, validate or improve.