Advertisement · 728 × 90

Posts by techy

detections.ai View and interact with detection rules shared by the community

This post is sponsored by detections.ai!

Tired of manually writing detection rules? detections.ai uses AI agents to convert threat intel into SIGMA, SPL, KQL, YARA rules automatically. Join 7,500+ detection engineers in the community. Use code "DEW" to get started: detections.ai

6 months ago 0 0 0 0

Threats: Microsoft seizes 338 RaccoonO365 sites, domains and panels, Two teenagers charged for London transport outage from August 2024, BlackLotus Labs latest research on SystemBC, Oliver Smith TTP updates for DPRK's BeaverTail malware family

6 months ago 0 0 1 0

* Garv Kamra's first foray into writing SIEM detections
* Jacob Zalesky first blog post ever (!) on threat hunting ideas in AWS

6 months ago 0 0 1 0

* Ryan Tomcik on co-occurring detection ideation using composite rules in Google SecOps
* Amitai Cohen's take on effective work & task prioritization with a gaming analogy near and dear to my heart (RTS games baby!)
* Hanif Kurniawan A. helps readers detect log source outages in Wazuh

6 months ago 0 0 1 0
Preview
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability power overwhelming

DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability

In this post:
* 💎 by Dirk-jan Mollema discloses a cross-tenant Azure vulnerability that gives access to any Azure tenant, with detection opportunities to boot!
www.detectionengineering.net/p/dew-130-go...

6 months ago 2 0 1 0
Preview
Detection Engineering Field Manual #1 - What is a Detection Engineer? Why does Detection Engineering matter to a security org?

I'm starting a new series on Detection Engineering called the Detection Field Manual. I wanted to publish < 10 minute reads on threat detection topics I've built in the field, at conferences and our interviews for candidates at Datadog.
Here's issue 1!
www.detectionengineering.net/p/detection-...

9 months ago 9 1 1 1
Preview
Datadog Detect: Scale your Security Operations with Detection Engineering | Datadog See metrics from all of your apps, tools & services in one place with Datadog's cloud monitoring as a service solution. Try it for free.

I'm so excited to announce that Datadog Security Research is launching a FREE, fully-online, Detection Engineering focused conference called Datadog Detect!

bit.ly/datadog-detect

Our lineup is incredible with experts in the field of detection, response and threat intelligence.

11 months ago 10 3 0 0
Post image

Found just outside Moscone North for RSA. Now I'm pumped for my talk tomorrow. #hacktheplanet

11 months ago 2 1 0 0
Advertisement
Preview
Det. Eng. Weekly #109 - I’m making a Hinge for detection engineers Your profile is a rule, an alert is a match, and a false positive is a shitty date

Detection Engineering Weekly Issue 109 is live! www.detectionengineering.net/p/det-eng-we...

1 year ago 4 2 0 0
Preview
Det. Eng. Weekly #108 - Can any1 in the IC add me to their Signal group? Just tryna forward some reels and feelin left out rn

Detection Engineering Weekly issue 108 is live! www.detectionengineering.net/p/det-eng-we...

1 year ago 5 0 0 0
Post image

@sekoia.io FYI your TLS cert is showing invalid due to date expiration for *.sekoia.io

1 year ago 2 0 1 0

I love it when you guys go deep into a topic. The deepseek episode was a great example.

1 year ago 3 2 0 0

Weekly: 1 hour
Deep dives: 2-3 hours

1 year ago 2 0 1 0

Browns coming in last yet again

1 year ago 3 0 0 0
Preview
2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.

🍎👿 The key macOS malware families of 2024: This past year saw a sharp rise in sophisticated campaigns targeting macOS users in the enterprise and the increasing adoption of cross-platform development frameworks.

1 year ago 11 4 1 0
Preview
Tracking Threat Actors with Validin | Validin Quickly identify threat actors and discover malicious infrastructure using Validin by viewing detailed descriptions on thousands of threat actors that Validin has cataloged

I’m biased, but wow—it’s so refreshing to get updates that genuinely help me better track threat actors. 🔥

www.validin.com/blog/threat_...

1 year ago 11 4 0 1
Advertisement

Bout to go wheels up!

1 year ago 3 0 1 0
Post image Post image Post image

Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?

1 year ago 40 8 2 1

There has been for years! Just starting to see it be more impactful

1 year ago 4 0 0 0
Notion Incident Management System (NIMS) | Notion Use the Template

🎉 link and docs and details: nims-template.notion.site

1 year ago 5 1 0 0
Logo for Notion Incident Management System (NIMS)

Logo for Notion Incident Management System (NIMS)

🚀 Excited to announce the alpha release of NIMS - a Notion-based Incident Management System!

Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.

#InfoSec #DFIR #IncidentResponse #SecOps #Notion

1 year ago 73 21 4 5

"North Korea-nexus Golang Backdoor/Stealer from Contagious Interview campaign" published by dmpdump. #ContagiousInterview, #DPRK, #CTI dmpdump.github.io/posts/NorthKorea_Backdoo...

1 year ago 1 2 0 0

Hi wanna “make plans”?

1 year ago 0 0 0 0
A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN

A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN

IF IT AINT EXECUTTABLE IT AINT FOR ME - dashare.zone ADMIN

1 year ago 350 45 0 5
Advertisement

Read the book twice and watched the series several times. Captain Winters is one of the top 3 leaders I try to emulate

1 year ago 2 0 0 0

We still have a “purity” problem in infosec. People want super technical resources but don’t want them to advertise anything to survive or grow their brand. They want a mold that looks like DEFCON 2005 and hate anything that looks different. Doesn’t seem very hacker to me 🤷

1 year ago 3 0 1 0

Even with the OPs main text, those are all great resources. There’s some actual charlatans like jonathandata1, but 95% of the people posted come from posters who seem just upset that they are not technical enough to their standards

1 year ago 2 0 1 0
Preview
From the cybersecurity community on Reddit Explore this post and more from the cybersecurity community

The cybersecurity subreddit has a thread on influencers and “who to avoid because of xyz”. These threads irk me because there’s no clear measurement and lots of gate keeping around who is allowed to post stuff and who isn’t. www.reddit.com/r/cybersecur...

1 year ago 4 0 2 0

I’ve been pretty sick for the last 2 weeks, but Christmas holiday has been a much needed break for rest and recovery.

Take care of yourselves people; I think stress contributed a ton to this, and being mindful and in the present has helped me out a lot.

And lots of Christmas food.

1 year ago 7 0 2 0