⤷ Title: From Pentest Findings to Falsifiable, Reproducible Proof
════════════════════════
𐀪 Author: Andreas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 10:09:16 GMT
════════════════════════
⌗ Tags: #automation_security #detection_engineering #application_security #pentesting
════════════════════════
𐀪 Author: Andreas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 10:09:16 GMT
════════════════════════
⌗ Tags: #automation_security #detection_engineering #application_security #pentesting
Medium
From Pentest Findings to Falsifiable, Reproducible Proof
Nuclei Templates as Detection Engineering, across pentest and threat-model assumptions
⤷ Title: Detection Engineering: The Skill Nobody Teaches You
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 06:55:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #threat_hunting #detection_engineering #ai
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 06:55:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #threat_hunting #detection_engineering #ai
Medium
Detection Engineering: The Skill Nobody Teaches You
Why modern security fails silently — and how building better detections actually changes outcomes.
⤷ Title: Detection Logic Bugs: Abusable Gaps in Detection Coverage
════════════════════════
𐀪 Author: Nikolas Bielski
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 07:05:04 GMT
════════════════════════
⌗ Tags: #threat_hunting #cloud_security #detection_engineering #hacking #information_security
════════════════════════
𐀪 Author: Nikolas Bielski
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 07:05:04 GMT
════════════════════════
⌗ Tags: #threat_hunting #cloud_security #detection_engineering #hacking #information_security
Medium
Detection Logic Bugs: Abusable Gaps in Detection Coverage
Detection Logic Bugs exist everywhere. Practitioners are starting to wake up. Vendor “100% Coverage” claims have a fallacy that leaves you…
⤷ Title: SigHunt — TryHackMe
════════════════════════
𐀪 Author: Nway Nway Zay Ya
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:55:40 GMT
════════════════════════
⌗ Tags: #detection_engineering #tryhackme_walkthrough #tryhackme #cybersecurity #writeup
════════════════════════
𐀪 Author: Nway Nway Zay Ya
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:55:40 GMT
════════════════════════
⌗ Tags: #detection_engineering #tryhackme_walkthrough #tryhackme #cybersecurity #writeup
Medium
SigHunt — TryHackMe
This is my walkthrough for SigHunt, a premium room from TryHackMe, part of the Detection Engineering module and SOC Level 2 learning path.
⤷ Title: Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 15:28:47 +0000
════════════════════════
⌗ Tags: #Open Source Tool #brute_force #Cyber Security 2026 #Detection Engineering #InfoSec Tool #Kerberos #Kerlab #Mimikatz #password spraying #Rubeus #Rust #TGS #TGT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 15:28:47 +0000
════════════════════════
⌗ Tags: #Open Source Tool #brute_force #Cyber Security 2026 #Detection Engineering #InfoSec Tool #Kerberos #Kerlab #Mimikatz #password spraying #Rubeus #Rust #TGS #TGT
Penetration Testing Tools
Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit
Explore Kerlab: A high-performance Rust tool for mastering Kerberos. From TGT/TGS requests to brute-forcing, build better detection rules with hands-on labs.
⤷ Title: The Autonomous Blue Team: Build a Self-Healing SIEM with the AI Detection Engineering Lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:13:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI security #Blue Team Automation #Claude Code #Detection Engineering #DevSecOps #Elastic Security #Fawkes C2 #MITRE ATT&CK #SIEM #Sigma Rules #Splunk #Threat Intel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:13:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI security #Blue Team Automation #Claude Code #Detection Engineering #DevSecOps #Elastic Security #Fawkes C2 #MITRE ATT&CK #SIEM #Sigma Rules #Splunk #Threat Intel
Penetration Testing Tools
The Autonomous Blue Team: Build a Self-Healing SIEM with the AI Detection Engineering Lab
Deploy an AI-powered detection pipeline using Claude Code. Automate the full SIEM lifecycle, from Sigma rule authoring to MITRE ATT&CK validation and tuning.
⤷ Title: Catching APT29 staging malware in 197k+ Sysmon events (and why your detection rule misses it)
════════════════════════
𐀪 Author: Manish Rawat
════════════════════════
ⴵ Time: Tue, 12 May 2026 12:01:01 GMT
════════════════════════
⌗ Tags: #infosec #blue_team #cybersecurity #threat_hunting #detection_engineering
════════════════════════
𐀪 Author: Manish Rawat
════════════════════════
ⴵ Time: Tue, 12 May 2026 12:01:01 GMT
════════════════════════
⌗ Tags: #infosec #blue_team #cybersecurity #threat_hunting #detection_engineering
Medium
Catching APT29 staging malware in 197k+ Sysmon events (and why your detection rule misses it)
Most SOC teams only watch process creation. I watch what processes load.
⤷ Title: Intro to Detection Engineering (THM) Tryhackme Walkthrough
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 27 May 2026 03:33:13 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #tryhackme #hacking #detection_engineering
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 27 May 2026 03:33:13 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #tryhackme #hacking #detection_engineering
Medium
Intro to Detection Engineering (THM) Tryhackme Walkthrough
Description : Learn what Detection Engineering is, how it works in a SOC, and the mindset required to build effective detections.
⤷ Title: Intro to Detection Engineering — THM WriteUp
════════════════════════
𐀪 Author: Sumit Shrestha
════════════════════════
ⴵ Time: Thu, 28 May 2026 15:35:52 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #detection_engineering #tryhackme #thm_writeup
════════════════════════
𐀪 Author: Sumit Shrestha
════════════════════════
ⴵ Time: Thu, 28 May 2026 15:35:52 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #detection_engineering #tryhackme #thm_writeup
Medium
Intro to Detection Engineering — THM WriteUp
Task 1: Introduction
⤷ Title: FortiClient EMS Was Turned Into a Malware Delivery System.
════════════════════════
𐀪 Author: Isaac Privett
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:46:00 GMT
════════════════════════
⌗ Tags: #endpoint_security #detection_engineering #red_team #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Isaac Privett
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:46:00 GMT
════════════════════════
⌗ Tags: #endpoint_security #detection_engineering #red_team #cybersecurity #penetration_testing
Medium
FortiClient EMS Was Turned Into a Malware Delivery System.
CVE-2026–35616 shows why endpoint management servers are not just admin consoles. They are fleet-wide execution platforms, and attackers…
⤷ Title: Intro to Detection Engineering (Refresh Ver.) Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:19:17 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #detection_engineering #tryhackme_walkthrough
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 10:19:17 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #detection_engineering #tryhackme_walkthrough
Medium
Intro to Detection Engineering (Refresh Ver.) Walkthrough Notes | TryHackMe
Learn detection engineering basics through practical concepts and security monitoring workflows.
⤷ Title: SigHunt — From IOCs to Sigma Rules: A Detection Engineering Walkthrough of TryHackMe — SigHunt
════════════════════════
𐀪 Author: Pravat Dash
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 20:26:18 GMT
════════════════════════
⌗ Tags: #detection #information_security #cybersecurity #tryhackme #security
════════════════════════
𐀪 Author: Pravat Dash
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 20:26:18 GMT
════════════════════════
⌗ Tags: #detection #information_security #cybersecurity #tryhackme #security
Medium
SigHunt — From IOCs to Sigma Rules: A Detection Engineering Walkthrough of TryHackMe — SigHunt
https://tryhackme.com/room/sighunt
⤷ Title: My First Steps in Purple Teaming with Atomic Red Team
════════════════════════
𐀪 Author: Boutros
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 10:49:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #detection_engineering #purple_team #ethical_hacking
════════════════════════
𐀪 Author: Boutros
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 10:49:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #detection_engineering #purple_team #ethical_hacking
Medium
My First Steps in Purple Teaming with Atomic Red Team
I just started a deep dive journey into Purple Teaming after finishing my four first years of engineering school. The first and main topic…
⤷ Title: How a Single KQL Query Stopped an Entire EvilTokens Phishing Campaign
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 21:29:58 GMT
════════════════════════
⌗ Tags: #detection_engineering #infosec #eviltokens #phishing #cybersecurity
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 21:29:58 GMT
════════════════════════
⌗ Tags: #detection_engineering #infosec #eviltokens #phishing #cybersecurity
Medium
How a Single KQL Query Stopped an Entire EvilTokens Phishing Campaign
Back in April of this year, an AI-powered phishing campaign known as EvilTokens took the spotlight in the infosec world. While the term…
⤷ Title: Detection Engineering With Snort | TryHackMe | detection challenge
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 03:18:52 GMT
════════════════════════
⌗ Tags: #snort #security_operation_center #tryhackme #cybersecurity #detection_engineering
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 03:18:52 GMT
════════════════════════
⌗ Tags: #snort #security_operation_center #tryhackme #cybersecurity #detection_engineering
Medium
Detection Engineering With Snort | TryHackMe | detection challenge
Build production-ready Snort detections: behaviour rules, tuning, suppression, and IOC lifecycle.
⤷ Title: Measuring Detection Engineering Effectiveness: A Practical Scorecard for Continuous Improvement
════════════════════════
𐀪 Author: Abhishek Kumar Sah
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 11:08:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #infosec #threat_detection
════════════════════════
𐀪 Author: Abhishek Kumar Sah
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 11:08:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #infosec #threat_detection
Medium
Measuring Detection Engineering Effectiveness: A Practical Scorecard for Continuous Improvement
Beyond False Positives — Part 2
⤷ Title: Finding the “Goldilocks” Zone: A Practical Approach to Alert Triage
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Active SOC #Blue Team #DFIR #Hayden Covington #Incident Response #Informational #Alert Traige #Detection Logic #Infosec for Beginners #InfoSec Survival Guide #Orange Book #SIEM
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Active SOC #Blue Team #DFIR #Hayden Covington #Incident Response #Informational #Alert Traige #Detection Logic #Infosec for Beginners #InfoSec Survival Guide #Orange Book #SIEM
Black Hills Information Security, Inc.
Finding the "Goldilocks" Zone: A Practical Approach to Alert Triage - Black Hills Information Security, Inc.
We're all petrified about missing a critical event or misclassifying an alert, but when we're talking about incident response (IR), there are often hundreds if not thousands of alerts to parse through. It's easy to get caught up with one alert because it…