Methodology
How the library is built
Quality bar
Read the DETECTION_QUALITY.md for the contribution standard. Each rule must include working query syntax, required data sources, prerequisites, expected volume guidance, false-positive guidance, tuning steps, and at least one framework mapping.
Authorship
Every rule is authored by a practitioner with field experience. No vendor-supplied marketing rules. Where a rule comes from a community contributor, attribution is permanent.
Stack realism
Each rule is mapped to one or more specific stack profiles. Where a rule cannot be implemented on a stack, that's stated explicitly with compensating controls.
Honest about limits
The library does not claim coverage where it doesn't exist. Personal-device, BYO-API-key, and mobile-data-plan channels remain hard or impossible to detect from the corporate environment; the library says so.
Review cadence
- Service signatures: monthly (LLM services move fast).
- Detection rules: quarterly (platform changes, query syntax evolution).
- Runbooks: annually or on a material program development.
- Stack profiles: quarterly.