Detection Engineering AI Maturity Framework
A community framework for assessing how organizations apply AI and large language models across a detection engineering program, from the involved people, processes, and technology to detection ideation, authoring, testing, tuning, and continuous improvement.
Framework overview
Section titled “Framework overview”Four maturity levels across ten dimensions (six Foundations plus four Detection Lifecycle).
Levels
Section titled “Levels”| Name | Defining trait | |
|---|---|---|
| L0 | None | No AI/LLM use in detection engineering. |
| L1 | Experimental | Ad-hoc individual use of public chatbots. No governance, no shared tooling, no evaluation. |
| L2 | Integrated | AI is embedded in team workflows with shared tooling, org-context RAG, policy, and human-in-the-loop review. |
| L3 | Autonomous | Agentic systems propose, test, and ship detections under guardrails with measurable ROI and continuous quality control. |
See Maturity Levels for full definitions and characteristic signals.
Dimensions
Section titled “Dimensions”Foundations
- Strategy & Governance
- People & Skills
- Tooling & Infrastructure
- Data & Knowledge
- Evaluation & QA
- Security, Privacy & Safety
Detection Lifecycle
- Detection Opportunity Ideation
- Detection Authoring
- Detection Testing & Validation
- Tuning, Coverage & Continuous Improvement
See The Matrix for the full level-by-level criteria.
Using this framework
Section titled “Using this framework”- Read The Matrix and the Maturity Levels.
- Score your organization against each dimension using the Self-Assessment guide.
- Identify gaps and prioritize the lowest-scoring dimensions that materially affect program safety.
Why this framework exists
Section titled “Why this framework exists”In recent years (possibly even months), AI in detection engineering has moved from curiosity and experimentation to operational reality. Many teams are somewhere on the journey from “individuals quietly use ChatGPT” to “agentic systems author and tune detections.” There isn’t a shared vocabulary for where any given team is on that journey, what the next step looks like, or prerequisites for moving forward.
This framework is my attempt at that vocabulary. It’s opinionated, vendor-neutral, and open-source so the community can correct, sharpen, and extend it.