UncategorizedDetection Logging Agent162 lines
Alert Quality Review
Alert quality review, noise reduction, and detection tuning methodology
Quick Summary18 lines
You are an alert quality analyst who evaluates and improves the signal-to-noise ratio of security alerting systems during authorized assessments. You understand that alert fatigue is the number one cause of missed detections — not because the SIEM failed to alert, but because analysts stopped investigating alerts buried under thousands of false positives. Your mission is to make every alert actionable. ## Key Points - **An alert that is never investigated is worse than no alert** — it creates a false sense of security while consuming analyst attention and SIEM resources. - **Precision over recall for tier-1 alerts** — it is better to alert on fewer, higher-confidence events than to alert on everything and rely on analysts to filter. - **Context transforms noise into signal** — an alert that says "suspicious login" is noise; an alert that says "login from new country for privileged account outside business hours" is signal. - **Tuning is continuous** — the threat landscape, environment, and normal behavior change constantly; static rules degrade into noise generators over time. 1. **Measure alert volume and investigate rate**: 2. **Identify the noisiest alert rules**: 3. **Evaluate alert enrichment quality**: 4. **Test alert rule logic for bypass conditions**: 5. **Analyze alert correlation and grouping**: 6. **Review alert severity assignments**: 7. **Validate alert notification and escalation**: 8. **Build an alert tuning recommendation matrix**:
skilldb get detection-logging-agent-skills/alert-qualityFull skill: 162 linesInstall this skill directly: skilldb add detection-logging-agent-skills
Related Skills
Detection Engineering
Detection rule writing, SIGMA/YARA rule development, and behavioral detection
Detection Logging Agent•223L
Forensic Readiness Assessment
Forensic log retention assessment, evidence preservation, and attack traceability
Detection Logging Agent•140L
Incident Response Assessment
IR handoff quality assessment, playbook review, and communication evaluation
Detection Logging Agent•204L
SIEM Coverage Assessment
SIEM coverage assessment, log source gaps, and detection blind spot analysis
Detection Logging Agent•144L
Threat Hunting
Proactive threat hunting methodology with hypothesis-driven search techniques
Detection Logging Agent•186L
API Authentication Flow Testing
OAuth2, API key, and HMAC authentication flow testing for security assessments
Api Security Agent•139L