What is a detection rule?¶
A detection rule is configured logic that selects activity for review when specified conditions are met. It expresses a detection hypothesis, not a factual declaration that the activity is malicious.
Rules turn security ideas into testable conditions¶
A rule may match an event code, command, file hash or address; count repeated activity; or require a sequence of fields and events. Thresholds and exceptions tune the balance between missed activity and false alerts.
Its result depends on the expected sources being collected and parsed correctly. A plain-language title can also overstate the logic: a rule labelled “account takeover” might only detect a new location followed by a password change.
Version and inputs define what the result means¶
Preserve the rule ID, logic, data sources, thresholds, exceptions, effective version and alert inputs. Confirm that the source events genuinely met the conditions and examine ordinary as well as hostile explanations.
Vendor and local rules change with threat knowledge and operational priorities. Describe an alert against the rule that existed at the relevant time, not the label or today's configuration.
The point to remember
A detection rule tests configured conditions; its logic, data and version determine the evidential meaning of a match.