[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fbt-detection-engineering-tuning":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","bt-detection-engineering-tuning","Bt Detection Engineering Tuning","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,40,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":8,"name":9,"count":11},{"key":41,"name":42,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":44,"name":45,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":47,"name":48,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":50,"name":51,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":157,"explanation":165},"019fad71-e70c-7296-b81c-76e41a735ec8",1,"In the simplest terms, what is a detection rule in a SOC's monitoring stack?",[153,156,159,162],{"key":154,"text":155},"a","A document listing every employee's login credentials for audit purposes.",{"key":157,"text":158},"b","A defined pattern or logic that, when matched against logs or files, triggers an alert for analyst review.",{"key":160,"text":161},"c","A firewall configuration that blocks all inbound traffic regardless of source, which is a network control mechanism rather than something that observes and flags suspicious activity for review.",{"key":163,"text":164},"d","A contract clause describing how long backups must be retained.","A detection rule encodes a pattern (a specific event sequence, field value, or file characteristic) that the monitoring platform evaluates continuously; when the pattern matches, it generates an alert for a human or automated workflow to triage.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":154,"explanation":178},"019fad71-e70f-7107-821a-36265d2dee9d","A rule fires an alert for activity that is later confirmed to be completely benign. What is this outcome called?",[170,172,174,176],{"key":154,"text":171},"A false positive — the rule matched, but there was no actual malicious or policy-violating activity.",{"key":157,"text":173},"A true negative, because the analyst eventually closed the ticket without escalation, which shows the underlying activity was correctly judged to require no further action.",{"key":160,"text":175},"A zero-day, because the activity had never been observed by the organization before.",{"key":163,"text":177},"A containment failure, because the workstation was not isolated immediately.","A false positive is an alert that fires without a genuine underlying incident. It differs from a true negative (no alert, no incident) and has nothing inherently to do with novelty or containment actions.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":163,"explanation":192},"019fad71-e716-7830-a72e-340474c543f5",2,"A detection rule fails to trigger during an actual intrusion that later gets discovered through other means. What is this missed detection called, and why is it dangerous?",[184,186,188,190],{"key":154,"text":185},"A true positive, because the intrusion was eventually discovered by any method available, regardless of whether the rule that was specifically built to catch it ever actually fired.",{"key":157,"text":187},"A tuning success, since the analyst workload for that period stayed low.",{"key":160,"text":189},"An escalation, because the incident was handled outside normal triage.",{"key":163,"text":191},"A false negative — the rule stayed silent during real malicious activity, so the attacker's dwell time increases undetected.","A false negative means genuine malicious activity occurred but no alert fired. It is often more dangerous than a false positive because it directly extends attacker dwell time and delays containment.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":157,"explanation":205},"019fad71-e71a-746a-9876-c212a7f96003","Sigma is widely used in detection engineering as a shared rule format. What is its main purpose?",[197,199,201,203],{"key":154,"text":198},"It replaces the need for a SIEM entirely, running detections directly on network cables, eliminating any requirement to collect, store, or query log data at all.",{"key":157,"text":200},"It is a generic, vendor-agnostic way to describe log-based detection logic so it can be translated into different SIEM query languages.",{"key":160,"text":202},"It only works for detecting malicious files stored on disk, not log events.",{"key":163,"text":204},"It is a malware family, and Sigma rules describe how to remove it from infected hosts.","Sigma is a community detection-rule format for log-based analytics: an analyst writes the logic once, and it can be translated\u002Fconverted for various SIEM backends, instead of writing the same detection in each vendor's native query syntax from scratch.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":154,"explanation":218},"019fad71-e71d-7702-ad38-8d16db7c19c9","YARA is another common tool in detection engineering. What kind of detection is it primarily designed for?",[210,212,214,216],{"key":154,"text":211},"Identifying files or in-memory content that match defined patterns, such as strings or structural characteristics associated with malware.",{"key":157,"text":213},"Correlating login events across multiple identity providers over a rolling 24-hour window, which depends on structured authentication log data rather than raw file or memory content.",{"key":160,"text":215},"Blocking outbound network connections based solely on destination country.",{"key":163,"text":217},"Generating executive dashboards that summarize quarterly compliance posture.","YARA is a pattern-matching tool oriented at files and memory content — it describes strings, byte patterns, or structural conditions that identify malware families or suspicious artifacts, rather than correlating log events across systems.",{"id":220,"topic":9,"difficulty":181,"body":221,"options":222,"correct_key":163,"explanation":231},"019fad71-e722-7ce0-b282-7e5be42e60f9","How would you summarize the core difference between Sigma and YARA in a detection engineering context?",[223,225,227,229],{"key":154,"text":224},"Sigma requires a paid license from a single vendor, while YARA is a proprietary format with no community adoption, so neither is suitable for open, cross-organization sharing of detection content.",{"key":157,"text":226},"Sigma and YARA are interchangeable names for the exact same rule syntax used by every SIEM vendor.",{"key":160,"text":228},"Sigma only detects network intrusions, while YARA only detects insider threats through HR records.",{"key":163,"text":230},"Sigma expresses detection logic over structured log events, while YARA expresses pattern matching over files or memory content.","The practical distinction is the data they operate on: Sigma targets structured log\u002Fevent data (e.g., authentication logs, process creation events) translated to SIEM queries, while YARA targets raw files or memory buffers for byte\u002Fstring pattern matches.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]