#DetectionEngineering
Reminder that in Feb I will teach a special, extended version of my #CTI + #DetectionEngineering & #ThreatHunting course with #OTsecurity examples and case studies at the #S4x25 conference!

s4xevents.com/s4x25-traini...
Training
s4xevents.com
November 18, 2024 at 1:59 PM
Summiting the Pyramid: Bring the Pain with Robust and Accurate Detection

medium.com/mitre-engenu...

#ThreatHunting #DetectionEngineering
Summiting the Pyramid: Bring the Pain with Robust and Accurate Detection
Written by Michaela Adams, Roman Daszczyszak, Steve Luke.
medium.com
December 23, 2024 at 10:58 AM
Hi, all. I'm new here, so let me introduce myself. I'm a #cybersecurity researcher for Splunk's #SURGe team. My background is Blue Team, especially the SOC and things closely associated with it (#ThreatHunting, #CTI, #DetectionEngineering, #DFIR).
November 19, 2024 at 9:20 PM
#100DaysofYARA 2025 edition begins tomorrow!

Any #CTI or #detectionengineering folks looking for a self-paced challenge to start the year with a laid back & fun community? Look no further!

The challenge is simple - write a YARA rule every day for 100 days
December 31, 2024 at 6:47 PM
🚨 Detect C2 Beacons!

New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!

🔗
academy.bluraven.io/blog/beaconi...

#ThreatHunting #DetectionEngineering #MDE
C2 Beaconing Detection with MDE Aggregated Report Telemetry
Detecting C2 Beaconing using MDE Aggregated Report Telemetry.
academy.bluraven.io
March 14, 2025 at 2:13 PM
🚀 Just launched: DetectionForge — a purpose-built platform for crafting, testing & validating @limacharlie.io detection rules.

Perform detection unit tests & multi-org backtesting + import/export IaC

🔗 Try it: detectionforge.ddi.sh
💻 GitHub: github.com/Digital-Defe... #detectionengineering #secops
DetectionForge
DetectionForge - A comprehensive detection engineering environment for crafting, validating, and testing LimaCharlie detection rules
detectionforge.ddi.sh
June 19, 2025 at 1:14 AM
The conclusion (part three) of our series on #DetectionEngineering is finally here! buff.ly/dijB0fy
March 10, 2025 at 4:48 PM
I’ll teach a rare, public, online session of my Paralus #CTI #CyberThreatIntel + #DetectionEngineering & #ThreatHunting (DE&TH) in July - register your interest at the following form:

forms.gle/AkdPY7pvQZ6o...
Paralus LLC: Threat Intel + DE&TH
Hello and thank you for your interest in a one-day workshop focusing on Cyber Threat Intelligence (CTI) core principles extended to Detection Engineering & Threat Hunting (DE&TH)! Scheduling: 14-17 J...
forms.gle
May 5, 2025 at 1:07 PM
Join @olafhartong.nl in his journey down the rabbit hole in search of new detection opportunities in the #Zeek telemetry embedded in Microsoft's EDR #MDE! Detection engineering is sometimes hard … 😎

falconforce.nl/detection-en...

#detectionengineering #kql #blueteam
December 16, 2024 at 2:40 PM
For the fourth consecutive year, we will be back in Las Vegas to facilitate our Advanced Detection Engineering in the Enterprise training!

Get your ticket before May 25. More information and registration: www.blackhat.com/us-25/traini...

#detectionengineering #training
February 14, 2025 at 11:06 AM
UTMStack - A customizable SIEM and XDR powered by real-time correlation and threat intelligence
Check it out 🔥🔥:
github.com/utmstack/UTM...

#threatintelligence #threathunting #SIEM #SOAR #detectionengineering #cybersecurity #infosec
GitHub - utmstack/UTMStack: Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.
Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence. - utmstack/UTMStack
github.com
January 27, 2025 at 1:26 AM
🚨To strengthen the #investigation and #detection capabilities of the Sekoia.io Threat Detection & Research (TDR) team, we are looking for a Senior Technical Threat Researcher!

www.welcometothejungle.com/fr/companies...

#CTI #DetectionEngineering
Sr Technical Threat Researcher - Sekoia.io - CDI - Télétravail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
www.welcometothejungle.com
January 29, 2025 at 1:59 PM
I'll be live in around 2 hours presenting and showcasing Stratus Red Team and Grimoire, two open-source tools for detection engineering!

cybr.com/webinars/adv...

16:30 CET / 10:30 EST

#detectionengineering
Adversary Emulation for the Cloud - Cybr
Learn how to emulate and detect adversaries by executing real-world attacks using open-source tools Stratus Red Team and Grimoire, created by our guest Christophe Tafani-Dereeper.
cybr.com
November 19, 2024 at 1:53 PM
🪪 Our new blog post explores the importance of Identity and Access Management (#IAM) event #detection.

We focus at how Sekoia.io set up detection rules for @okta and @JumpCloud technologies.

blog.sekoia.io/iam-detectio...

#DetectionEngineering #Cloud #SOCplatform
December 21, 2023 at 10:23 AM
PANIX - Persistence Against *NIX
An excellent Linux persistence tool for detecting persistence mechanisms
Check it out 🔥🔥
#cybersecurity #infosec
#linuxpersistence
#securityresearch #detectionengineering #pentesting

github.com/Aegrah/PANIX
August 2, 2024 at 2:40 AM
These posts are mainly focused on topics of #ThreatResearch, #VulnerabilityResearch , #DetectionEngineering , getting people comfortable with #Snort and #Suricata, and #Homelab

Enjoy!
April 25, 2026 at 9:39 PM
🛡️ Discover the first part of Sekoia.io's in-depth series on detection engineering at scale! This new report offers a holistic approach to tackle the myriad challenges faced by SOC and #DetectionEngineering teams.

https://buff.ly/3ZWGU3c
December 16, 2024 at 3:34 PM
⏳ Not long to wait until our live webinar with Google Cloud Security.

Don't miss the opportunity to hear @jamieb.com and Piergiorgio Di Giacomo discuss strategies for mastering #detectionengineering.

rsvp.withgoogle.com/events/maste...
December 3, 2024 at 12:35 PM
I will hold a Paralus #CyberThreatIntelligence (CTI) + #DetectionEngineering & #ThreatHunting (DE&TH) ONLINE training from 26-29 OCT, 1400-1600 US Eastern. Details and cost in the Google Form. Please register your interest for high-velocity, low-cost #Infosec training!

forms.gle/um8L3QfiTetV...
Paralus LLC: Threat Intel + DE&TH
Hello and thank you for your interest in an online course and workshop focusing on Cyber Threat Intelligence (CTI) core principles extended to Detection Engineering & Threat Hunting (DE&TH)! Scheduli...
forms.gle
August 17, 2026 at 9:10 PM
When you group your logs by timestamp(binning) to detect threats, you probably cause false negatives. Solve it using sliding window counts!

academy.bluraven.io/blog/advance...

#KQL #ThreatHunting #DetectionEngineering
Advanced KQL for Threat Hunting: Window Functions — Part 2
Sliding window functions are one of the powerful methods for accurate detections as they eliminate the potential false negatives. They can be used in threat hunting, detection engineering, and DFIR to...
academy.bluraven.io
February 28, 2025 at 3:52 PM
Recently something interesting happened.

My research on DLL hijacking detection was referenced in work from the National Cyber Security Centre (Cyber Defence Analysis).
www.linkedin.com/posts/manish...

#sysmon #cybersecurity #threathunting #detectionengineering #medium #substack #infosec #events
#cybersecurity #informationsecurity #substack #threathunting #sysmon #detectionengineering | Manish Rawat
I didn’t expect this. Recently, my research on DLL hijacking detection was referenced in CTO at NCSC – Cyber Defence Analysis. The section titled: “37 Sysmon Events. One Complete DLL Hijacking Attac...
www.linkedin.com
March 13, 2026 at 3:33 AM