Topic hub

Detection Engineering

Writing, tuning, and testing detections: Sigma rules, YARA signatures, Suricata/Snort, threat hunting, and the telemetry pipeline that turns an attack into an alert before it becomes an incident.

31 articles

API Security

Identity Threat Detection

Incident Response

Ransomware Defense

Windows Threat Detection

Detection Engineering

Detecting BYOVD Attacks

How to detect BYOVD (bring-your-own-vulnerable-driver) attacks — the driver-load and service-creation signals, a Sigma rule, the LOLDrivers list, and HVCI hardening.

14 min read

Active Directory Attacks

Email Security

Threat Hunting

Network Threat Detection

Detection Engineering

C2 Beaconing Detection

How to detect C2 beaconing without ML — interval regularity, jitter analysis, and JA3 fingerprints over Zeek logs, with an SPL analytic and egress hardening.

14 min read
Detection Engineering

DNS Tunneling Detection

How to detect DNS tunneling without an ML model — query length, entropy, and frequency thresholds, a Suricata rule and a Zeek/SPL analytic, plus egress hardening.

14 min read

Cloud Security

Detection as Code

Web Application Defense