Detection Rules and Alerts SecuSiem — Detection Rules and Alerts
SecuSiem implements a two-layer detection system:
Regex-based rules with MITRE ATT&CK mapping for fast pattern matching
Claude AI analysis for contextual threat assessment and false positive reduction
SecuSiem ships with 10 detection rules covering key MITRE ATT&CK tactics:
Field Value Severity Critical MITRE Tactic TA0001 - Initial Access MITRE Technique T1190 - Exploit Public-Facing Application Threshold 1 match Patterns UNION SELECT, SELECT FROM WHERE OR, DROP TABLE, INSERT INTO, command delimiters (--, ;, /*)
Field Value Severity High MITRE Tactic TA0001 - Initial Access MITRE Technique T1190 Threshold 1 match Patterns <script>, javascript:, event handlers (onerror=, onload=), <iframe>
Field Value Severity High MITRE Tactic TA0006 - Credential Access MITRE Technique T1110.001 - Password Guessing Threshold 5 matches in 300 seconds Patterns Failed password for ... from ... port ... ssh, authentication failure.*user=
Field Value Severity High MITRE Tactic TA0005 - Defense Evasion MITRE Technique T1083 - File and Directory Discovery Threshold 1 match Patterns ../, /etc/passwd, /etc/shadow, URL-encoded variants
Field Value Severity Critical MITRE Tactic TA0002 - Execution MITRE Technique T1059 - Command and Scripting Interpreter Threshold 1 match Patterns Shell commands (cat, wget, curl, nc, bash), command chaining (&&, `
Field Value Severity Critical MITRE Tactic TA0004 - Privilege Escalation MITRE Technique T1068 - Exploitation for Privilege Escalation Threshold 1 match Patterns sudo su, passwd root, chmod +s
Field Value Severity Medium MITRE Tactic TA0007 - Discovery MITRE Technique T1552 - Unsecured Credentials Threshold 1 match Patterns /etc/shadow, /etc/passwd, .ssh/id_rsa, .aws/credentials, .docker/config.json
Field Value Severity High MITRE Tactic TA0010 - Exfiltration MITRE Technique T1048 - Exfiltration Over Alternative Protocol Threshold 3 matches in 600 seconds Patterns curl -X POST, wget -O, scp @:
Field Value Severity Medium MITRE Tactic TA0006 - Credential Access MITRE Technique T1110 - Brute Force Threshold 10 matches in 300 seconds Patterns HTTP 401/403, Unauthorized, Forbidden
Field Value Severity Medium MITRE Tactic TA0001 - Initial Access MITRE Technique T1190 Threshold 1 match Patterns sqlmap, nikto, nmap, masscan, metasploit, havij, acunetix, nessus, burp, empty User-Agent
The check_log_against_rules() function processes each log message:
def check_log_against_rules (log_message: str ) -> List[Dict]:
matches = []
for rule in DETECTION_RULES :
for pattern in rule[ "patterns" ]:
if re.search(pattern, log_message, re. IGNORECASE ):
matches.append({
"rule_id" : rule[ "rule_id" ],
"rule_name" : rule[ "name" ],
"severity" : rule[ "severity" ],
"mitre_tactic" : rule[ "mitre_tactic" ],
"mitre_technique" : rule[ "mitre_technique" ],
})
break # Only report first match per rule
return matches
After regex preprocessing, matched logs are sent to Claude for contextual analysis:
Sonnet 4.5 (default): Quick analysis for routine detections
Opus 4.5 (add-on): Deep analysis for complex threat scenarios ($150/analysis)
The AI provides:
Contextual threat assessment
False positive identification
Recommended remediation actions
Threat severity scoring
The claude-analyzer runs a background task (configurable interval, default 300 seconds) that:
Queries Loki for recent logs per tenant
Applies detection rules
Sends context to Claude API
Generates alerts in the PostgreSQL database
Updates tenant usage records
Tactic ID Tactic Name Rules TA0001 Initial Access sql-injection, xss-attempt, malicious-user-agent TA0002 Execution command-injection TA0004 Privilege Escalation privilege-escalation TA0005 Defense Evasion path-traversal TA0006 Credential Access brute-force-ssh, unauthorized-api-access TA0007 Discovery suspicious-file-access TA0010 Exfiltration data-exfiltration