Detection engineering
SignalHunt
A real detection rule catalogue — Sigma-style rules with MITRE ATT&CK mapping, required log fields, and the audit policy that actually produces them — plus incident write-ups chaining rules across a full attack lifecycle, and articles on detection engineering methodology.