04 · Monitor
Detection Health
Catch dead rules, noisy rules, drift, failing tests, missing telemetry and weak mappings before they become blind spots.

- 01 One Backlog for dead rules, drift, failed tests, false positives, missing telemetry, and missing metadata.
- 02 Owner-targeted notifications when deployed rules go silent or change out of band.
- 03 Noise budgets and monitoring mode protect analysts before alerts go live.
Outcomes
What this changes for the team.
Signal
Know when a rule stops working
Per-rule health, firing history, tests and source coverage expose silent failures before an incident does.
Control
Noise is budgeted
Rules that exceed expected volume can be held, tuned, or left in monitoring mode.
Audit
Drift is visible
Out-of-band SIEM edits are hashed, diffed, and queued for review.
The problem
Shipping a rule is not the end of detection engineering. Rules go silent because logs change, fields drift, integrations break, upstream products update, or someone edits the detection directly in the SIEM. Other rules keep firing but become too noisy for analysts to trust.
Traditional dashboards make this hard to see. Noise, rule health, test failures, coverage, direct SIEM edits, and missing metadata often live in different places. By the time a team notices, the first reliable signal may be an incident review.
How CraftedSignal monitors detections
CraftedSignal keeps health signals attached to the rule lifecycle. Each deployed rule can show recent firing behavior, test status, drift state, false-positive pressure, noise budget impact, ownership, platform deployment state, source coverage, and related risk.
The platform surfaces one Backlog for rules and telemetry that need attention: dead rules, unexpectedly noisy rules, drifted rules, failing tests, missing ATT&CK mappings, missing owners, missing log sources, and other quality issues. The queue is designed for action, not just observation.
Backlog items turn those signals into next steps: tune this rule, add tests, fix this mapping, enable this telemetry, review stale runbooks and playbooks, generate a rule for this coverage gap, or retire low-value content.
Noise, drift, and silent failure
Noise budgets set an expected alert volume by company, team, service, or rule. New detections can run in monitoring mode first, producing measurement without paging analysts. If expected volume is too high, the rule can be tuned before it becomes active.
Drift detection compares the running SIEM version to the version CraftedSignal last deployed. If a rule changes outside the controlled workflow, the platform shows the diff and queues it for review. That protects both auditability and operational trust.
Silent rules are handled as a first-class health issue. When a rule that normally fires stops producing signal, the owner can be notified and the SOC can decide whether telemetry changed, the threat disappeared, or coverage broke.
What leaders get
SOC leaders get a Monday-morning view of the work that matters: runtime risk, broken detections, noisy detections, uncovered techniques, missing telemetry, and workload. The goal is not to count rules. The goal is to know which protections are alive, which need attention, and which risks remain open.
Related docs
Go deeper in the technical docs.
Health & Analytics
Coverage, health queues, workload metrics, MTTD, MTTR, and ROI views.
Drift Detection
How deployed rules are re-hashed, diffed, and reviewed after out-of-band changes.
Noise Budgets
Daily alert limits by company, team, service, and rule.
Backlog
Risk-scored action queue for coverage, tuning, telemetry, mappings, and stale response steps.
Generation Quality
Owner-facing metrics for generation quality, retries, errors, and proposals.
Git-native Backups
Scheduled Git mirrors for rules, versions, tests, and restore points.
Next feature sets