Detection engineering teams are increasingly adopting automation to monitor and maintain the effectiveness of deployed detection rules. Maintenance of detection rules is a critical but often neglected aspect, with many organizations facing challenges such as excessive alert volumes and insufficient allow-listing, leading to alert fatigue and missed threats. Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms typically provide limited native support for ongoing monitoring and tuning of detection rules, necessitating custom solutions. To address these gaps, detection engineers are implementing automated checks to track the trigger rates of detections, monitor the frequency of entities triggering alerts, and detect tampering such as unauthorized disabling or deletion of rules. Health metrics, including daily and monthly failure rates of detection rules, are also being tracked to ensure ongoing operational integrity. Automation in this phase enables proactive maintenance, allowing teams to address issues before they escalate to the Security Operations Center (SOC) or customers. In parallel, the security community is actively updating detection rules across multiple repositories, with recent changes including the addition of 47 new rules and modification of 81 existing ones in a single week. These updates target a range of threats, such as Windows defense evasion techniques, malicious scheduled tasks, and cloud environment persistence tactics. Notably, new rules have been introduced to detect attempts to disable Windows Event Log services and to identify malicious use of scheduled tasks leveraging tools like curl and PowerShell. Detection coverage for Azure and Microsoft 365 has been enhanced, focusing on defense evasion methods like deleting firewall policies and disabling cloud logs, as well as persistence via privileged role assignments and illicit OAuth consent grants. Email security rules have also evolved, now incorporating advanced analysis techniques such as optical character recognition (OCR), logo detection, and natural language understanding (NLU) to better identify phishing attempts and reduce false positives. These developments reflect a broader trend toward continuous improvement and operationalization of detection engineering, with automation and community-driven rule updates playing a central role in strengthening organizational defenses against evolving threats. By integrating automated monitoring and leveraging the latest detection rule advancements, security teams can more effectively manage alert volumes, reduce manual workloads, and improve their ability to detect and respond to sophisticated attacks.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.