By the end of A5, you will have one connected fictional package showing how a professional defender moves from mission risk and evidence to behavior hypotheses, logic, testing, tuning, documentation, quality review, ownership, and leadership communication.
Artifact 1
Fictional detection-engineering purpose, mission risk, stakeholders, scope, exclusions, authorization, and safety boundary
Artifact 2
Asset, identity, service, supplier, administrative, wireless, DNS, evidence, and recovery detection-priority map
Artifact 3
Defender-question catalog with decision use, non-proof statement, evidence needs, owner, priority, and review trigger
Artifact 4
Data-source inventory with provenance, fields, freshness, completeness, timing, schema, transformation, duplication, coverage, privacy, and source health
Artifact 5
Behavior-hypothesis library with expected state, meaningful deviation, identity, destination, sequence, time, peer context, alternatives, and confidence
Artifact 6
Conceptual detection-logic specifications with conditions, windows, counts, sequences, relationships, exclusions, missing-data behavior, severity, and limits
Artifact 7
False-positive, false-negative, expected-alert, unknown-outcome, source-degraded, and coverage-gap review register
Artifact 8
Detection-tuning and contextual-enrichment plan with owners, evidence, exceptions, expiration, validation, metrics, and rollback
Artifact 9
Alert-to-defender-question matrix with evidence requests, triage context, escalation criteria, unresolved states, and closure requirements
Artifact 10
Synthetic detection-test package with invented positive, negative, boundary, maintenance, change, degraded-source, privacy, edge, and regression cases
Artifact 11
Detection documentation packet with purpose, sources, logic, assumptions, severity, testing, tuning, response guidance, privacy, ownership, dependencies, and lifecycle
Artifact 12
Detection-quality metrics plan covering coverage, precision, noise, missed conditions, source health, analyst usefulness, review time, and residual risk
Artifact 13
Multidisciplinary detection-review findings, disagreement log, owner actions, completion criteria, validation results, and reopened issues
Artifact 14
Leadership summary, technical appendix, analyst guide, portfolio reflection, and complete fictionalization statement