← back to case studies
Running internally, design partner engagedInternal

SIEM detection pipeline

A detection pipeline on OpenObserve with OCSF normalization, risk scoring, and Sigma rules converted to VRL, running internally with an enterprise design partner engaged, ahead of planned productization.

OpenObserveOCSFSigmaVRLThreat intel
architecturescroll to pan →
IAMNetworkCloudTrailOCSFnormalize · scoreSigma → VRLdetectionsAlertsrisk scoredThreat intel

Problem

Detection engineering needs normalized events, consistent risk scoring, and portable rules that run against real IAM, network, and CloudTrail telemetry, without locking into a single vendor rule format.

My role

Building the pipeline: OCSF normalization, Sigma authoring and conversion to VRL, threat intelligence integration, and an in-progress LLM-powered Sigma-to-VRL conversion pipeline.

What shipped

  • +OCSF normalization with event categorization and risk scoring
  • +Sigma rules authored and converted to VRL
  • +Detections running against IAM, network, and CloudTrail telemetry
  • +Integrated threat intelligence feed
  • +LLM-powered Sigma-to-VRL conversion pipeline: in progress

Outcome

  • Running internally with an enterprise design partner engaged, ahead of planned productization