CyberHire

25 Detection Engineer Interview Questions and Answers

25 detection engineer interview questions with what each one tests and what a strong answer includes, from Sigma and KQL to tuning, testing and coverage.

These 25 detection engineer interview questions are for the person hiring: a detection engineering lead, SOC manager or Head of Security. They cover fundamentals, real scenarios from running a detection programme, and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down groups them by focus, from writing rules to measuring coverage.

A detection engineer’s work is judged by two numbers nobody sees in an interview: how many real attacks their rules catch, and how many false alarms they cost the SOC. The questions below test both sides: writing logic that catches behaviour, and tuning it so analysts trust it. For questions that apply to every cyber role, see the main list of cyber security interview questions.

Detection engineer interview questions on the fundamentals

Use two or three to check the foundations. Strong candidates answer with rules they have written and tuned, not definitions.

QuestionWhat it testsWhat a strong answer includes
1. What makes a detection good?Quality barIt catches the behaviour it is meant to, rarely fires on anything else, tells the analyst what to do next, and is documented, tested and mapped to a technique.
2. What does detection-as-code mean in practice?Engineering disciplineRules kept in version control, changed through peer-reviewed pull requests, tested automatically against sample data, and deployed through a pipeline with a way to roll back.
3. What is Sigma, and why would you use it?Portable detection logicA vendor-neutral rule format written in YAML that converts into queries for different SIEMs. Makes rules easier to share, review and move between platforms. See Sigma.
4. What is the Pyramid of Pain, and how does it shape what you detect?Detection strategyIndicators such as hashes and IP addresses are trivial for an attacker to change; tools and especially behaviours are much harder. So the most durable detections target techniques, not indicators.
5. How do you balance false positives against false negatives?Trade-offsToo many false positives bury real alerts and wear out analysts; too few means real attacks get through. Sets the balance per detection based on how severe the behaviour is and what it costs to triage.
6. What telemetry would you need to detect credential dumping from LSASS?Data knowledgeProcess access events against lsass.exe, for example Sysmon Event ID 10, or EDR telemetry, and knows which access rights are suspicious. Maps it to MITRE ATT&CK T1003.001.
7. How do you measure detection coverage?Honest measurementMaps detections to the techniques that matter for the organisation’s threat model, then tests that each one actually fires. Counting rules is not coverage.

Scenario-based detection engineer interview questions

These show how a candidate runs a detection programme, not just writes a rule. Listen for whether they think about the analysts who receive the alerts.

QuestionWhat it testsWhat a strong answer includes
8. A detection fires 300 times a day, almost always on benign activity. Its owner wants it disabled. What do you do?Tuning over deletingWorks out what the benign activity is, adds narrow exclusions, or turns it into a lower-severity signal that only alerts when combined with others. Does not switch it off without understanding what it would miss.
9. A red team reached domain admin and nothing fired. Where do you start?Gap analysisRebuilds the red team’s timeline and, for each step, checks whether the telemetry existed, whether a detection existed, whether it fired, and whether it was triaged. Each failure has a different fix.
10. A new threat report describes a ransomware group. How do you turn it into detections?Intelligence to detectionPulls out the techniques, not just the indicators, maps them to ATT&CK, checks existing coverage, and builds and tests the missing detections. Uses indicators only as short-term additions.
11. A log source your detections rely on stops sending data. How would you know?Silent failureMonitors ingestion volume and delay per source, alerts when a source goes quiet, and treats a missing source as an incident in its own right.
12. How do you test a detection before it goes live?ValidationRuns it against recorded attack data or a safe simulation of the technique, checks its false positive rate against historical logs, and deploys it in alert-only or low-severity mode first.
13. Analysts say your alerts lack context. What do you change?Serving the SOCAdds enrichment such as asset owner, user role and recent related alerts, explains in the alert why it fired, and links to a triage runbook.
14. Attackers keep using legitimate admin tools. How do you detect that without drowning in noise?Living-off-the-landBaselines normal use per host and user, watches for unusual parent and child processes and command lines, and combines several weak signals instead of alerting on any single one.
15. Your company is moving to a new SIEM. What happens to the detections?MigrationInventories detections, prioritises by value, rewrites and retests them for the new platform’s field names (Sigma helps), runs both systems in parallel, and confirms the new rules fire on the same test data.
16. An attack was missed because the attacker obfuscated the command line. What do you do?Resilient logicDetects on behaviour and process relationships rather than exact strings, decodes or normalises where possible, and uses PowerShell script block logging, which records the deobfuscated script.
17. How do you decide which detection to build next?PrioritisationWeighs the organisation’s threat model, current intelligence, known coverage gaps, lessons from incidents and red team exercises, and the effort involved.

Hands-on detection engineer interview tasks

Short tasks to run in the interview with demo data. Watching a candidate write and tune a real rule tells you more than any answer above.

TaskWhat it testsWhat a strong answer includes
18. Write a Sigma rule that detects PowerShell downloading content from the internet.Rule writingA valid rule with the right log source, selection and condition, plus known false positives and a severity. See the example below.
19. Here is a Sigma rule and five events it matched. Which are true positives?Rule comprehensionReads the rule logic precisely, judges each event in context, and explains why a match is not automatically malicious.
20. Write a KQL query that detects a password spray.Querying behaviourCounts distinct accounts with failed sign-ins per source address within a time window, rather than failures per account. See the example below.
21. Here is a noisy rule and a week of its alerts. Tune it.TuningGroups the alerts, identifies the benign patterns, and writes exclusions narrow enough not to hide real attacks.
22. Here is a detection with no documentation. Write it.DocumentationPurpose, ATT&CK mapping, data source, logic, known false positives, severity reasoning and triage steps.
23. Map these ten detections to ATT&CK and show the gaps for a ransomware threat.Coverage thinkingA clear map of what is covered and what is not, with the most important gaps ranked.
24. Here is a log source. What could you detect with it?Creativity with dataFor example, from DNS logs: tunnelling, randomly generated domains, newly registered domains and unusual query volumes.
25. Review this pull request to the detection repository.Peer reviewSpots logic errors, wrong field names, missing tests and queries that would be too expensive to run.

For task 18, a reasonable Sigma rule looks like this:

title: PowerShell Download Cradle
status: experimental
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    Image|endswith: '\powershell.exe'
    CommandLine|contains:
      - 'DownloadString'
      - 'DownloadFile'
      - 'Invoke-WebRequest'
  condition: selection
falsepositives:
  - Admin scripts that download from internal servers
level: medium

A strong candidate will point out that it misses pwsh.exe and obfuscated command lines, and say how they would cover both.

For task 20, one answer in Microsoft Sentinel uses Entra ID sign-in failures with error code 50126 (invalid username or password):

SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == "50126"
| summarize Accounts = dcount(UserPrincipalName) by IPAddress, bin(TimeGenerated, 1h)
| where Accounts > 10

Which questions for which kind of detection role?

Some detection engineers mostly write rules. Others run the programme and the pipeline around them. Pick from the areas the person will own.

FocusWhat it coversQuestions to use
Writing detectionsRule logic, Sigma and queries3, 6, 16, 18, 19, 20, 25
Tuning and qualityNoise, context, documentation1, 5, 8, 13, 14, 21, 22
Coverage and strategyThreat models, ATT&CK, priorities4, 7, 9, 10, 17, 23
Data and engineeringPipelines, log sources, testing2, 11, 12, 15, 24

For candidates coming from SOC analyst roles, add some of the SOC analyst interview questions to check their triage instincts.

What are the red flags in a detection engineer interview?

  • Indicators instead of behaviour. Every detection idea is a hash, domain or IP address.
  • No thought for the analyst. Measures success by the number of rules written, not by whether the alerts are useful.
  • No testing. Assumes a rule works because it was deployed.
  • Disables instead of tunes. Switches off noisy rules without understanding what they would have caught.
  • Cannot read the data. Writes rules against field names they have never checked in the real logs.

Why a hands-on task beats any detection engineer interview question

Anyone can describe a good detection. Writing one that catches the attack and stays quiet the rest of the time is the skill, and it only shows when the candidate works with real telemetry.

portal.cyber-hire.com/challenge/kql Microsoft Sentinel Detection engineer interview alternative: a KQL lab with a query editor over SigninLogs and SecurityAlert tables, a schema tree and a results grid returning 520 records, with a question asking which IP address was used for the password spray attack.
No hint about which table matters. The candidate has to know what a password spray looks like in sign-in telemetry and express it as a query, which is task 20 done for real.

Used before the interview, this shows you who can turn an attack technique into working logic. The interview can then focus on tuning judgement, coverage strategy and how they work with the SOC.

Frequently asked questions

What does a detection engineer do?

A detection engineer designs, builds, tests and maintains the rules that turn security telemetry into alerts. They decide what to detect, write the logic, tune it so it is accurate, and work with the SOC so the alerts are useful.

What is the difference between a detection engineer and a SOC analyst?

A SOC analyst responds to alerts. A detection engineer creates and improves the detections that produce them. Many detection engineers start as SOC analysts, which gives them a feel for what makes an alert useful.

What skills does a detection engineer need?

Query languages such as KQL or SPL, rule formats such as Sigma, a solid understanding of attacker techniques and the telemetry that shows them, and engineering habits like version control and testing.

How do you test a detection engineer before the interview?

Give them real telemetry and ask them to find or detect a specific attack, or give them a rule and some events and ask them to separate true positives from false positives. Score the logic and how they explain it.

How CyberHire tests detection engineers before the interview

CyberHire is cyber technical screening that shows you who can write a detection that works before you book an interview. Pick from the library or paste your job specification and generate an assessment. Candidates work in real environments: KQL hunting labs against realistic sign-in and endpoint telemetry, Sigma rule true and false positive triage, Windows event log investigations, and detection rule authoring and tuning.

Every candidate is scored the same way, with integrity signals next to each score, and you see their queries and reasoning. Detection engineers are one of the roles we assess; see all use cases. If you would rather not build the assessment yourself, our team will build it with you.

Hiring a detection engineer?

See who can write a detection that works before you interview anyone.

Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Real telemetry, real rules, scored the same way for every candidate.

Get a free assessment Request a sample report