Running internally, design partner engagedInternal
SIEM detection pipeline
A detection pipeline on OpenObserve with OCSF normalization, risk scoring, and Sigma rules converted to VRL, running internally with an enterprise design partner engaged, ahead of planned productization.
OpenObserveOCSFSigmaVRLThreat intel
architecturescroll to pan →
Problem
Detection engineering needs normalized events, consistent risk scoring, and portable rules that run against real IAM, network, and CloudTrail telemetry, without locking into a single vendor rule format.
My role
Building the pipeline: OCSF normalization, Sigma authoring and conversion to VRL, threat intelligence integration, and an in-progress LLM-powered Sigma-to-VRL conversion pipeline.
What shipped
- +OCSF normalization with event categorization and risk scoring
- +Sigma rules authored and converted to VRL
- +Detections running against IAM, network, and CloudTrail telemetry
- +Integrated threat intelligence feed
- +LLM-powered Sigma-to-VRL conversion pipeline: in progress
Outcome
- →Running internally with an enterprise design partner engaged, ahead of planned productization