Published inDetect FYIIntroducing > PowerShell.ExposedCommunity-driven pattern-based detection indicators2d agoA response icon12d agoA response icon1
Published inDetect FYIRethinking Benign Alerts: A New Perspective for Detection EngineeringBreaking down the false TP/FP dichotomy in the SOCDec 10, 2025A response icon1Dec 10, 2025A response icon1
Published inDetect FYIIntroducing the DRAPE Index: How to measure (in)success in a Threat Detection practice?Going Beyond the Cosmetics to Assess Detection QualityNov 17, 2025A response icon4Nov 17, 2025A response icon4
Published inDetect FYIMalicious Encoded PowerShell: Detecting, Decoding & ModelingThe challenges and insights from dealing with this PS one-linerAug 25, 2025Aug 25, 2025
Published inDetect FYIThe Detection Opportunity CostWhat should drive picking one detection idea over another?May 1, 2025A response icon3May 1, 2025A response icon3
Published inDetect FYIBecoming a Detection Engineering Contractor, Part II— The PreparationYou want to become a contractor or an independent consultant in the Detection Engineering (DE) space? This series is for you.Mar 26, 2025A response icon1Mar 26, 2025A response icon1
Published inDetect FYIThreat Hunting step-by-step: Collecting Web Shells 🐚 using Ephemeral BaselinesTurning a KQL hunting query into a Defender detection rule to spot unusual web server processes using simple statistics.Feb 25, 2025A response icon1Feb 25, 2025A response icon1
Published inDetect FYIBaselines 101: Building Resilient, Frictionless SIEM DetectionsHow to leverage Enterprises' Circadian Window to spot unusual activity and potentially uncover cyber threats.Feb 12, 2025A response icon1Feb 12, 2025A response icon1
Published inDetect FYIBecoming a Detection Engineering Contractor, Part I — The MotivationSo you wanna become a contractor (freelancer, independent consultant) in the Detection Engineering space? Here I share my impressions.Jan 17, 2025A response icon3Jan 17, 2025A response icon3
Published inDetect FYIFrom Intelligence to Detection: A Workflow for Integrating CTI, IR, Hunting & Red TeamsIn 2017, a former software tester suggested that I should consider shipping detection content by following the SDLC, and it seemed like a…Nov 3, 2024A response icon3Nov 3, 2024A response icon3