Fun with AGI Part 1: “GET AGI TO WRITE YOUR SENTINEL DETECTION RULES” (without it eating y
Fun with AGI Part 1: “GET AGI TO WRITE YOUR SENTINEL DETECTION RULES” (without it eating your SIEM)
AI wrote it, CI tested it, SOC approved it.
Untested code is available upon request to any friends.
Everyone’s talking about “AI-assisted threat detection.” Most of it is bad PowerPoint ju-ju.
Here’s what actually works when you want an agent to write KQL rules that make sense and don’t set your SOC on fire.
Step 1 — Give it context, not the keys.
Feed the AGI your threat-intel feeds (STIX/TAXII, MISP, RSS) and a read-only mirror of historical telemetry. Let it observe, not act.
Step 2 — Make it output like an adult.
Force it to produce four things every time:
• A KQL rule (rule.kql)
• A Sentinel analytic rule payload (rule.json)
• Metadata (who wrote it, why, confidence)
• A tiny back-test spec (time range, cost budget, expected hits).
Step 3 — Automate your paranoia.
CI/CD runs validate.py to lint, block wildcards, and laugh at bad YAML.
Then backtest.py hits a dev Sentinel workspace, runs the query, measures false-positive blast radius and query cost.
Step 4 — Human eyes before production lies.
Each rule opens a pull request with results, sample hits, and AGI rationale.
A SOC lead reviews it like any other code change.
If it passes, the pipeline injects the KQL into the JSON and deploys via:
az sentinel alert-rule create --resource-group RG --workspace-name WS --rule-id RULEID --scheduled-alert-rule @rule.json
Step 5 — Never trust the robot, but let it do the chores.
The AGI becomes your unpaid junior: it drafts the Sigma-style logic, writes the playbook stub, and explains why it thinks “explorer.exe launching cmd.exe” is sketchy.
You just say yes or no.
Net effect:
→ New detections in hours, not weeks.
→ Audit trail of every rule, prompt, and test.
→ Zero production access for the machine.
Congratulations, you’ve built an autonomous detection engineer that works for free and can’t file an HR complaint.
Future you will thank current you when the next “AI-driven threat” headline drops and your SOC quietly hums along, fully agentic, beautifully sandboxed, and still under human command.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·