Skip to content

Dimensions

This framework assesses ten dimensions of AI/LLM use in detection engineering, grouped into Foundations (people, process, and technology) and Detection Lifecycle (tactical operations).

These dimensions aren’t unique to detection engineering. They apply to any team adopting AI. But they have specific weight here because detection engineering operates on sensitive telemetry, ships code that runs against production data, and lives or dies on signal quality.

These dimensions describe AI use at each stage of the detection lifecycle, from detection opportunity ideation to authoring, testing, tuning, and continuous improvement. They’re the dimensions where AI directly touches detection content and outcomes.

Each dimension page contains four sections:

  1. What it covers. The scope of the dimension.
  2. Why it matters for AI in Detection Engineering. The specific risks and opportunities that make this dimension worth assessing.
  3. Level descriptors. The four maturity levels for this dimension, verbatim from the matrix.
  4. Anti-patterns. Common failure modes I’ve seen worth watching for.