Build an automated detection testing framework with GitLab CI/CD and Duo
Blog post from GitLab
GitLab's Signals Engineering team created a custom framework called Weekly Attack Testing for Continuous Health (WATCH) to ensure the reliability of their security operations center (SOC) alerting system. WATCH addresses the challenge of silent failures in detection systems by simulating real-world malicious behavior on owned infrastructure and validating whether alerts are properly triggered and routed through their security monitoring stack, which includes Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) systems. This automated framework operates on a GitLab CI/CD pipeline, running weekly tests at random intervals to prevent detection timing issues, and uses notifications to differentiate between test-generated and real alerts. WATCH enhances detection validation by closing gaps not covered by their existing GitLab Universal Automated Response and Detection (GUARD) system and provides real-time visibility into detection health via interactive dashboards hosted on GitLab Pages. By proactively identifying detection failures before actual incidents occur, WATCH improves detection reliability and allows GitLab to replay tactics, techniques, and procedures (TTPs) from past security operations to validate detection rules.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 1 | 7,450 | 1,704 | 292 | -47% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.