Write the rule, not the ticket. Author Sigma and KQL detections against real adversary telemetry, then watch them scored on true positives AND false positives against a held-out benign data set.
0
of 1000 • 0/10
There is no answer key for your rule. Every rule you submit is executed against a data set of real-shaped malicious and benign events, and the score comes out of what it actually caught: half the marks for recall, half for precision. A rule that finds the attack but also fires on the nightly backup job loses points, and the lab tells you exactly which benign event tripped it. Tune and resubmit as often as you like - your best attempt is the one that counts.