Hack.lu 2026

OpenTIDE Workshop – Build Your Own Operational DetectionOps Platform in 90 Minutes

Threat-informed detection engineering is often difficult to operationalise: security teams must transform cyber threat intelligence into actionable detections while managing tooling complexity, detection coverage, and operational workflows.

This hands-on workshop builds on the talk “OpenTIDE – Threat-Informed Detection Engineering Made Easy” and guides participants through deploying their own operational OpenTIDE platform using GitHub or GitLab. Participants will configure documentation pipelines, explore Detection-as-Code workflows, and learn how OpenTIDE JSON Schemas integrate with IDEs such as VS Code or Kiro to simplify YAML authoring through validation and auto-completion when describing threat vectors, defining detection objectives or implementing and deploying detection rule custom queries tuned from Sigma or any available sources.

The workshop also includes a demonstration of the full Managed Detection Rule lifecycle using a staging Splunk Enterprise Security environment.

Participants will leave with a working OpenTIDE deployment and the practical foundations required to start building threat-informed DetectionOps capabilities in their own organisations.


This 90-minute hands-on workshop follows the session “OpenTIDE – Threat-Informed Detection Engineering Made Easy” and enables participants to immediately put threat-informed detection engineering concepts into practice.

OpenTIDE is the threat-informed detection engineering framework developed at the European Commission CSOC and used operationally since 2022. It combines Threat & Detection Modelling, Detection-as-Code, documentation generation, CI/CD workflows, and reporting capabilities into a unified DetectionOps platform.

During the workshop, participants will deploy and configure their own OpenTIDE environment using InitTide on their git solution (GitLab and GitHub fully supported). They will learn how to structure and manage Threat Vectors (TVM), Detection Objectives (DOM), and Managed Detection Rules (MDR) while applying Git-based workflows and peer-review practices.

The workshop will cover:

  • OpenTIDE deployment and repository initialisation

  • Documentation pipeline configuration

  • Threat & Detection Modelling concepts

  • Detection-as-Code workflows

  • ATT&CK coverage reporting and visualisation

  • Sharing detection content through ShareTIDE and MISP

  • IDE integration using OpenTIDE JSON Schemas for YAML validation and auto-completion

Special attention will be given to the detection engineering authoring experience. Participants will learn how IDEs such as VS Code, Kiro, or other schema-aware editors simplify YAML object creation and validation using OpenTIDE schemas.

A dedicated staging Splunk Enterprise Security environment will demonstrate the full Managed Detection Rule lifecycle, from modelling and rule development to deployment and operational validation.

The workshop will also briefly introduce AgentTide and how agentic workflows can assist detection engineers when working with OpenTIDE objects and detection content.

Participants should leave the workshop with:

  • Their individual functioning OpenTIDE repository hosting their objects

  • A configured documentation generation pipeline and the wiki pages of the objects published on their own OpenTIDE instance

  • good understanding of the IDE-assisted YAML authoring capabilities including AgentTide of OpenTIDE

  • Practical experience with threat-informed DetectionOps workflows in particular on how to take any detection rule and turn it into an operational detecion on their platforms.

The workshop is intended for SOC analysts, detection engineers, CTI practitioners, and defenders interested in operationalising threat intelligence and Detection-as-Code practices.

Prerequisites

Participants should bring:

Required

  • Laptop with Wi-Fi capability
  • GitHub account or GitLab account (SaaS or self-managed) for the full experience. Any git for the DetectionOps.
  • Modern web browser
  • IDE configured and connected to Git repositories
  • VS Code, Kiro, or another IDE capable of JSON Schema integration and YAML auto-completion
  • Basic Git familiarity (repositories, commits, pull requests / merge requests)

Recommended

  • Familiarity with YAML
  • Familiarity with MITRE ATT&CK concepts
    Basic SOC, CTI, or detection engineering experience

Notes

  • No Splunk knowledge is required.
Remi Seguy

With over 25+ years in the cybersecurity field, I have dedicated my career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- I have actively contributed to the cybersecurity community and related open-source projects, such as MISP. In my current role, I have led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. I am looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.