A working knowledge base for Adversarial Detection Engineering (ADE): reasoning about the false negatives in SIEM/EDR/XDR detection rules — the mismatches between what a rule intends to catch and what it actually catches — before a threat actor abuses them.
It packages the ADE taxonomy as worked technique files, platform-specific bug-pattern references, pre-engagement scoping tooling, and a Redamon skill, all grounded in analysis of real public detection rulesets (Sigma, Elastic Security, Microsoft Sentinel).
Defensive use only. This material is for detection engineering, purple-team scoping, and risk assessment. Obtain explicit written authorization before testing detections or systems you do not own or operate. See each technique's own guardrails.
Four categories of detection-logic bug, 16 subcategories, 38 worked technique files:
ADE1 — Reformatting in Actions (the logged input is reshaped so a string match fails)
ADE1-01 Substring Manipulation
ADE1-02 Normalization Asymmetry
ADE2 — Omit Alternatives (an in-scope alternative is not enumerated by the rule)
ADE2-01 Method / Binary
ADE2-02 Versioning
ADE2-03 Locations
ADE2-04 File Types
ADE3 — Context Development (surrounding context is shaped, not the primary action)
ADE3-01 Process Cloning
ADE3-02 Aggregation Hijacking
ADE3-03 Timing and Scheduling
ADE3-04 Event Fragmentation
ADE3-05 Lineage Spoofing
ADE3-06 Limit Saturation
ADE4 — Logic Manipulation (Boolean / filter / field logic is inverted or wrong)
ADE4-01 Gate Inversion
ADE4-02 Conjunction Inversion
ADE4-03 Incorrect Expression
ADE4-04 Field Mismapping & Semantics
Start with the category overviews: ADE1 · ADE2 · ADE3 · ADE4.
Adversarial_Detection_Engineer/
ade_framework/
ADE1..ADE4/ category overview + per-subcategory folders
ADEn-NN-<subcategory>/ README + one .md per worked technique
detection-logic-bugs.md theory: what a detection-logic bug is
bug-likelihood-test.md fast pre-analysis heuristic for a rule
mitigations.md fixes by ADE category + per-platform section
experiment.md
bug_patterns/ cross-cutting + platform bug catalogs (see its README)
ade-checklist.md the four false-negative lenses in depth
rulesets.md where to find public rulesets and how to search them
redamon/ Redamon-packaged skill (ade_scoper) + README
| I want to… | Go to |
|---|---|
| Understand the theory | detection-logic-bugs.md |
| Triage a rule quickly | bug-likelihood-test.md · ade-checklist.md |
| See worked technique files | the ADEn-NN-*/ folders under ade_framework |
| Fix a vulnerable rule | mitigations.md (incl. per-platform sections) |
| Platform-specific pitfalls | bug_patterns/ — Elastic · Sentinel · Sigma |
| Scope a purple-team engagement | rulesets.md · redamon/ade_scoper.md |
| Browse the raw findings catalog | total_candidate_bugs.md — 605 candidate bypass findings across Elastic/Sentinel/Crowdstrike/Sigma |
Each worked file carries YAML frontmatter (id, title, ade_category, ade_subcategory, named mitre_attack tags, platform, testable) and a common body structure: Summary → ADE Classification → The Technique → Vulnerable Rule → Hardened Rule → Detection Layers → Implementation Nuances → References. Summary, ADE Classification, Detection Layers, and Implementation Nuances appear in every file; the remaining sections are typical but not universal. Several files are grounded in specific real findings, carrying a Documented instances table naming the affected vendor rules.
- Nikolas Bielski — co-author & lead maintainer (GitHub · LinkedIn)
- Daniel Koifman — co-author & maintainer (GitHub · LinkedIn)
MIT. Attribution required. Provided "as is" without warranty of any kind.
Intended solely for defensive security research, detection engineering, and risk assessment. Users are responsible for complying with all applicable laws, regulations, and authorization requirements. Detection rules and monitoring content are generally out of scope for vendor vulnerability disclosure and bug-bounty programs; treat examples with responsible-disclosure considerations.