DETECTION ENGINEERING / RAPID7 INSIGHTIDR + SOPHOS
Reduce the noise.
Keep the signal.
Sophos Detection Engineering & False Positive Reduction
Designed, implemented, and tuned custom detection content in Rapid7 InsightIDR to centralize Sophos Intercept X threat telemetry and support SOC triage. The focus was recurring detections that accurately described activity but, after investigation, represented expected business operations.
01 / OBJECTIVE
Make alerts actionable.
Centralize Sophos Central threat telemetry in Rapid7, investigate recurring detection families, reduce avoidable analyst work, and retain visibility into genuine malicious behavior.
Built and maintained custom detection content for endpoint threat telemetry. Investigation connected each alert to process lineage, parent-child relationships, service-account context, vulnerability scanning, and relevant ATT&CK techniques.
02 / INVESTIGATION
Understand the behavior first.
Investigated recurring endpoint alerts by reviewing process lineage, digital signatures, file consistency, and business context. Correlated multiple observations to distinguish expected application behavior from activity requiring further investigation.
Also reviewed alerts associated with authorized scanning and monitoring. The investigation focused on whether the observed behavior was consistent with an approved operational purpose.
03 / TECHNICAL CHALLENGE
Validate the data model.
Initial exception matching did not behave as expected. Investigated the difference between displayed log attributes and searchable SIEM fields, then validated the appropriate field mappings.
This troubleshooting work improved the reliability of detection queries and reinforced the importance of testing assumptions about normalized telemetry.
04 / TARGETED TUNING
Reduce noise carefully.
Developed narrowly scoped exceptions for validated business activity and reviewed the remaining detections to preserve visibility into unexplained behavior.
The approach combined investigation, query validation, and targeted tuning. Exact rule conditions and operational configurations are not included in this public summary.
05 / OUTCOME & LEARNING
A repeatable tuning process.
- Reduced recurring alerts from approved business applications.
- Improved the signal-to-noise ratio through targeted exceptions.
- Preserved visibility into suspicious malware-related and remote-service activity.
- Established a workflow: investigate context, validate fields, narrow the exception, and review the remaining detections.
The central lesson was that detection quality depends on understanding both the telemetry schema and the business context. A valid behavioral detection can still require tuning when the activity is expected.
Results are described qualitatively; no measured reduction percentage is claimed. This case study summarizes my project work. Detection identifiers, rule logic, field mappings, application identifiers, internal hostnames, service-account names, raw logs, and customer information are omitted.