Free snapshot slots open this week info@inversez.com
DetectionVulnerabilitiesToolsAuditsPricingBlogFree monitoring assessmentContact
Home/Detection

Detection engineering, on-chain and in the SIEM.

The same discipline applied to two very different telemetry sources. Decide what "wrong" looks like, express it precisely enough to check automatically, tune it until the alert is trustworthy, and write down what to do when it fires. Most of the value is in the last two steps, which is the part tooling vendors leave to you.

They are the same job.

A SIEM rule and an on-chain invariant are the same object wearing different syntax. Both start with a claim about what normal looks like. Both fail the same way: written once against a sample, never validated against the real environment, never tuned, and quietly muted six weeks later by whoever is on shift.

The skills that make detection content survive contact with production — knowing the difference between a rule that fires and a rule that is useful, measuring false positives before shipping, writing the triage step — transfer directly. The query language is the easy part.

The web2 practice is running in production today for a US client on Splunk. The on-chain practice is newer, and the library is where you can judge the reasoning for yourself before engaging us.

One practitioner.

There is no on-call team here and no 24/7 desk. Alerts route to you. Where a response window is part of the engagement, it is a stated window in working hours, written into the contract rather than implied by a marketing page.

We would rather scope that honestly and be useful inside it than sell coverage we cannot staff.