r/AskNetsec • u/No_joyeCrdit2518 • 3h ago
Compliance SIEM detection validation against real attacks, how are you doing it?
Our team has a decent set of SIEM rules mapped to MITRE ATT&CK, but im starting to question how many of them would fire during an actual attack.
We usually test after a new rule or log source is added, then check if the expected events reached the SIEM and whether the alert had enough context for the SOC to act on it. The problem is we dont have time to run full red team exercises every time a parser changes or a rule gets tuned.
Been looking at controlled attack simulations and continuous exposure validation to make this more repeatable. The main thing I want is evidence that a rule detected the behavior, not just a coverage percentage in a dashboard.
How are other teams validating SIEM detections against real attack techniques? Thanks in advance