Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a detection rule?

A detection rule is a set of conditions used by a security product to decide that activity is worth flagging.

It might look for a known malicious file, a suspicious command, an unusual login pattern, repeated failures or a particular sequence of events.

For an investigator, the important question is what did the rule actually test?

Rules turn events into alerts

TelemetrySystem recordsProcess, login, file, network or other events.
RuleConditions appliedPattern, threshold, sequence or indicator.
AlertMatch reportedSeverity, label and affected objects.

The alert inherits the strengths and weaknesses of both the telemetry and the rule.

Rules make trade-offs

A broad rule may catch more suspicious activity but also generate more noise.

A narrow rule may be very specific but miss slightly different behaviour.

For example:

Rule approach Possible strength Possible weakness
Exact file hash Very specific match Misses changed files
Command pattern Can catch behaviour Legitimate admin may match
Failed-login threshold Highlights brute-force-like activity Busy systems may create noise
Unusual-location model Finds abnormal access VPNs and travel may confuse it

That is why the rule name alone is not enough.

Capture the version that existed at the time

If a rule matters to the case, record:

  • rule ID;
  • name;
  • version;
  • logic or conditions;
  • data sources;
  • thresholds;
  • exclusions;
  • severity/confidence;
  • enabled state;
  • recent changes.

A rule may have been tuned after the incident.

You need the logic that actually produced the alert.

No alert does not prove nothing happened

A rule may not fire because:

  • the relevant telemetry was missing;
  • the rule was disabled;
  • the activity used a different technique;
  • a threshold was not reached;
  • the rule did not exist yet.

So absence of an alert is not the same as absence of activity.

The practical point is: understand the rule, the data it used and the version in force. Then you can explain why the alert appeared — or why it did not.

Reference: CIM-017Cyber Incidents & Offender Methods