TECHNOLOGY & SAAS

Detection-as-code that
ships with the product.

A high-growth SaaS platform put detections in the same pipeline as its code — and cut false positives 71% while covering a cloud that redeploys hourly.

INDUSTRY
B2B SaaS platform
SIZE
900 engineers · multi-region
DEPLOYMENT
BYOC · customer AWS
REGION
Global
FALSE-POSITIVE RATE↓ 71%
BEFOREbaseline
WITH DETECTION-AS-CODE−71%
tested detections · shipped in CI
THE CHALLENGE

Security that couldn't keep up with deploys.

Orbital shipped a hundred times a day into a cloud that reprovisioned itself hourly. Static rules written on Monday were stale by Wednesday, and every new microservice was a coverage gap the SOC learned about after an alert — or after an incident.

WHERE IT HURT
  • Infrastructure redeployed faster than rules could be written
  • New services shipped with no detections
  • False positives drowned a nine-person team
  • No way to version, test, or review a detection
THE APPROACH

Detections in the same pipeline as the code.

Orbital adopted threatDefendr's detection-as-code workflow: rules live in Git, ship through CI with backtests, and deploy alongside the service they protect. Behavioral models cover the parts no one wrote a rule for.

Detections ship in the same pull request as the feature now. Security stopped being the thing that slowed the release train.
SL
Sofia Lindqvist
Head of Security, Orbital
WHAT CHANGED

The outcome, measured.

71%
FEWER FALSE POSITIVES

Tested, peer-reviewed detections cut the noise that was burning out a nine-person team.

Same PR
DETECTION SHIPS WITH CODE

Every new service now arrives with its detections already in CI.

Hourly
CLOUD COVERAGE HOLDS

Behavioral models keep pace with infrastructure that redeploys every hour.

// TECHNOLOGY & SAAS

Detection-as-code that
ships with the product.

A high-growth SaaS platform put detections in the same pipeline as its code — and cut false positives 71% while covering a cloud that redeploys hourly.

INDUSTRY
B2B SaaS platform
SIZE
900 engineers · multi-region
DEPLOYMENT
BYOC · customer AWS
REGION
Global
// FALSE-POSITIVE RATE↓ 71%
BEFOREbaseline
WITH DETECTION-AS-CODE−71%
tested detections · shipped in CI
// THE CHALLENGE

Security that couldn't keep up with deploys.

Orbital shipped a hundred times a day into a cloud that reprovisioned itself hourly. Static rules written on Monday were stale by Wednesday, and every new microservice was a coverage gap the SOC learned about after an alert — or after an incident.

WHERE IT HURT
  • Infrastructure redeployed faster than rules could be written
  • New services shipped with no detections
  • False positives drowned a nine-person team
  • No way to version, test, or review a detection
// THE APPROACH

Detections in the same pipeline as the code.

Orbital adopted threatDefendr's detection-as-code workflow: rules live in Git, ship through CI with backtests, and deploy alongside the service they protect. Behavioral models cover the parts no one wrote a rule for.

Detections ship in the same pull request as the feature now. Security stopped being the thing that slowed the release train.
SL
Sofia Lindqvist
Head of Security, Orbital
// WHAT CHANGED

The outcome, measured.

71%
FEWER FALSE POSITIVES

Tested, peer-reviewed detections cut the noise that was burning out a nine-person team.

Same PR
DETECTION SHIPS WITH CODE

Every new service now arrives with its detections already in CI.

Hourly
CLOUD COVERAGE HOLDS

Behavioral models keep pace with infrastructure that redeploys every hour.