Skip to content
Back to work
Detection Engineering

SOC Detection Alerts — Custom Splunk Detection Engineering

Nine custom, MITRE ATT&CK-mapped Splunk detections built end-to-end in a self-built Linux/Windows lab — each attack manually executed, its telemetry captured firsthand, and the resulting alert validated against real logs.

The Problem

Detection rules are easy to write against clean, pre-packaged sample data. Proving a detection actually works means generating the attack yourself, capturing what it really looks like in the logs, and confirming the alert fires correctly — with no shortcuts.

Objective

To design, implement, and validate a set of custom detection alerts covering attacker behavior across the Authentication, Privilege Escalation, Execution, and Persistence MITRE ATT&CK tactics.

Approach

  • Built a lab environment with Linux and Windows endpoints, forwarding authentication, process execution, PowerShell, and service-creation activity into Splunk.
  • For each of the 9 alert scenarios, personally executed the corresponding attacker behavior on the endpoint — for example, running `sudo adduser test4` to simulate unauthorized local user creation — generating first-party telemetry rather than relying on a pre-built dataset.
  • Wrote SPL detection logic per alert, including field extraction and scheduled trigger conditions with throttling tuned to reduce noise.
  • Validated every alert against the logs generated from these live simulations, capturing evidence of the attack, the triggered alert, and the detection result for each.

Tools & Technologies

  • Splunk
  • SPL

Outcome

9 validated, MITRE ATT&CK-mapped detection alerts, each fully documented with its detection objective, log sources, SPL query, trigger condition, attack simulation steps, validation evidence, false-positive considerations, and SOC-style response guidance. Categories span SSH brute-force and successful-login-after-failure (Authentication), local user creation and privileged group additions on both Linux and Windows (Privilege Escalation), suspicious PowerShell and parent-child process execution (Execution), and suspicious service creation (Persistence).

Lessons Learned

  • Good detections are tuned to reduce noise — throttling and trigger conditions matter as much as the underlying detection logic.
  • Detections built around behavior patterns, rather than single events, hold up better against false positives.
  • Documenting false-positive scenarios up front — like legitimate admin account provisioning — is what turns a detection from a proof-of-concept into something a real SOC team could actually run.

Links