Accepting, for a moment, that Detection and Response Ops by way of detection engineering is the way of the future for any security operations organization with hopes of keeping IR event counts low and analyst sanity high, it's easy to wonder at why there are so very few models out there for doing it properly. We're here to describe a relatively simple framework for scalable, intelligence led D&R operations that pivots on publicly available components and should be within the realm of feasibility for any competent team.