cd ../work
[ blue-team ][ detection-as-code ][ building ]
07

DetectForge

LLM-assisted detection-as-code pipeline

Work in progress
[ building ]

Building an LLM-assisted detection-as-code pipeline that turns a raw threat-intel report into a validated, ATT&CK-mapped Sigma rule with an automated test, compressing intel-to-deployment from days to minutes. Every rule is generated, converted to SIEM queries, sandbox-validated against an Atomic Red Team test, and opened as a pull request, so it’s proven to fire before it merges.

[ ← back to work ]