Detection content needs more than a query
A useful detection should explain what behavior it identifies, which data it requires, how it can be validated and what conditions may create noise.
Calyvex Detect is a future toolkit direction for packaging those elements together so detection content is easier to review, test and maintain.
Proposed content model
Each detection package may include a rule, behavioral description, telemetry requirements, ATT&CK mapping, test procedure, expected results, known false-positive conditions and tuning history.
Current status
The solution is an active design direction. Reusable detection content will be added as Lab projects are completed and validated.