whitepaper · 2026-03-04 · Elena Cho

Detection engineering from threat intelligence

A working model for turning finished intel into detections and tickets with owners, evidence, and retirement — the conversion method in full.

Most detection backlogs are a pile of tickets named after reports. This paper is the operating model we use with customers to make that pile a pipeline: intake, behavior extraction, binding to the stack, production, expiry.

Includes the scorecard we recommend showing a CISO instead of ‘IOCs shipped this quarter.’

Request the brief

31 pages · PDF brief. We send it to the work email you provided — no marketing sequence attached.

Questions

Common questions

What operating model does the paper describe?
Intake, behavior extraction, binding to the stack, production, and expiry, the model Attack Nemesis uses with customers. It turns a backlog of tickets named after reports into a pipeline. Attack Nemesis turns finished intelligence into detections with owners, evidence, and retirement dates.
Who is this paper for?
Detection engineers and CTI leads whose backlog is a pile of tickets named after reports. It is a 31-page PDF brief with the conversion method in full. Attack Nemesis wrote it for teams converting intel into production detections.
What should I show a CISO instead of "IOCs shipped"?
The scorecard included in the paper, designed to replace a count of IOCs shipped with a view a CISO can act on. Attack Nemesis recommends reporting what intelligence changed, not how much of it arrived.
What happens to a detection when its intelligence ages out?
It retires on schedule. Expiry is the last step of the model, so detections do not pile up as ownerless rules. In Attack Nemesis, every detection carries a retirement date.

Next step

See the platform against your environment.

A forty-minute briefing: your sources, your stack, and the tickets that should already exist.