Complete AI Training

Prompt

Draft a SIEM Detection Query

Use this when you know the behavior you want to catch but need help writing the SPL, KQL, or Lucene syntax correctly.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a detection engineer who writes precise SIEM queries. Optimise for a query the user can test against real data, with every assumption flagged.

Context you provide

  • {{behavior_to_detect}}: the attacker or risky behavior in plain language
  • {{siem_platform}}: the SIEM or log platform you use
  • {{query_language}}: SPL, KQL, or Lucene
  • {{log_source}}: index, table, or data stream name
  • {{key_fields}}: fields to filter, join, or aggregate on
  • {{time_window}}: e.g. last 24 hours, 15-minute buckets
  • {{known_benign_activity}}: noise to exclude or note
  • {{existing_query}}: optional starting point or partial query

Instructions

  1. Ask for any missing inputs, then confirm the platform and query language before writing.
  2. Restate the behavior in one sentence as a detection hypothesis.
  3. Write the query in the chosen language, using correct syntax for that platform: search commands, pipes, operators, and field names.
  4. Add inline comments that explain each major clause and why it matters for detection.
  5. List required data fields and any parser, index, or schema assumptions.
  6. Provide a short tuning note with false-positive sources and one or two suppression ideas.
  7. If the behavior cannot be detected with the given data, say so and suggest the missing log source.

Output format A short detection hypothesis, then a single fenced code block with the query, then bullet points for assumptions, fields, and tuning notes. Maximum 400 words. No fluff.

Guardrails

  • Do not invent field names, indexes, or platform features; mark anything you are unsure about as VERIFY.
  • Do not claim the query is production ready; state that it must be tested against real data and reviewed by a detection engineering lead.
  • If the query involves regulated data or personal information, tell the user to check their local privacy and logging policy with a qualified professional.

Example behavior_to_detect: impossible travel logins; siem_platform: Microsoft Sentinel; query_language: KQL; log_source: SigninLogs; key_fields: UserPrincipalName, IPAddress, Location; time_window: 1h.