I analysed the 2025 Red Team assessment to turn offensive observations into concrete detection-engineering work. The assessment covered external attack, an IT foothold and an OT foothold, each with different operational consequences and data requirements.
For each observed technique or detection signal, I recorded its ATT&CK mapping, attack stage, execution outcome and operational impact. I then assessed what the SOC could plausibly detect, the telemetry it would need and the likely fidelity of the signal. This connected prioritisation to the activity demonstrated in the assessment.
I produced a living backlog that separated rule development and hunting opportunities from telemetry and other engineering prerequisites. That distinction made dependencies visible before work was assigned: some use cases needed data or attribution improvements before useful detection logic could be built.
I prepared a redacted version for MDR collaboration and proposed the next steps: confirm existing coverage, assign build or tuning ownership and plan purple-team validation. The delivered result was the analysis and prioritised backlog, ready to feed the governed detection lifecycle.
Closer to the work
From observation to use case
I analysed 29 observed techniques or detection signals across three scenarios. Each assessment considered ATT&CK technique, execution stage, impact, detection feasibility, required telemetry and likely fidelity. The purpose was to identify useful defensive observations from the exercise and express them as engineering requirements.
Open this detail ↗A backlog that records dependencies
The analysis produced 26 prioritised backlog items spanning detection, hunting, telemetry and engineering work. These recorded candidate work and dependencies; implementation status needed to be tracked separately. The backlog allowed the MDR and internal teams to discuss what could be built with current data and what required another team’s input.
Open this detail ↗Validation as a planned next step
I proposed checking existing coverage against the observed activity, assigning missing-data and rule-development work, and using purple-team testing to validate the resulting detections. This placed testing after implementation and kept an ATT&CK mapping distinct from evidence that a detection actually worked.
Open this detail ↗Skills established through this work