Maintaining a detection catalog in the LLM era
My last two posts were about building detections faster. The first covered getting a language model to write queries that match your real telemetry instead of its imagination. The second covered packaging the whole workflow as a coding-agent plugin, so every rule goes through the same gates from draft…