Security Engineering / Detection Use Cases

Turn Red Team findings into engineering priorities

Mapped 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering items, with ATT&CK mappings and telemetry dependencies.

UK Water UtilityDetection use-case analysis and prioritisation2 min read

I analysed the 2025 Red Team assessment to turn offensive observations into concrete detection-engineering work. The assessment covered external attack, an IT foothold and an OT foothold, each with different operational consequences and data requirements.

For each observed technique or detection signal, I recorded its ATT&CK mapping, attack stage, execution outcome and operational impact. I then assessed what the SOC could plausibly detect, the telemetry it would need and the likely fidelity of the signal. This connected prioritisation to the activity demonstrated in the assessment.

I produced a living backlog that separated rule development and hunting opportunities from telemetry and other engineering prerequisites. That distinction made dependencies visible before work was assigned: some use cases needed data or attribution improvements before useful detection logic could be built.

I prepared a redacted version for MDR collaboration and proposed the next steps: confirm existing coverage, assign build or tuning ownership and plan purple-team validation. The delivered result was the analysis and prioritised backlog, ready to feed the governed detection lifecycle.

Closer to the work

From observation to use case

I analysed 29 observed techniques or detection signals across three scenarios. Each assessment considered ATT&CK technique, execution stage, impact, detection feasibility, required telemetry and likely fidelity. The purpose was to identify useful defensive observations from the exercise and express them as engineering requirements.

Open this detail ↗
A backlog that records dependencies

The analysis produced 26 prioritised backlog items spanning detection, hunting, telemetry and engineering work. These recorded candidate work and dependencies; implementation status needed to be tracked separately. The backlog allowed the MDR and internal teams to discuss what could be built with current data and what required another team’s input.

Open this detail ↗
Validation as a planned next step

I proposed checking existing coverage against the observed activity, assigning missing-data and rule-development work, and using purple-team testing to validate the resulting detections. This placed testing after implementation and kept an ATT&CK mapping distinct from evidence that a detection actually worked.

Open this detail ↗

Skills established through this work

This work connects to

Security engineeringDetection engineering

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.