techy's Avatar

techy

@techy.detectionengineering.net

Creator of Detection Engineering Weekly (https://detectionengineering.net), Sec Research/Intel/Detection @ Datadog

1,558
Followers
404
Following
70
Posts
05.06.2023
Joined
Posts Following

Latest posts by techy @techy.detectionengineering.net

detections.ai View and interact with detection rules shared by the community

This post is sponsored by detections.ai!

Tired of manually writing detection rules? detections.ai uses AI agents to convert threat intel into SIGMA, SPL, KQL, YARA rules automatically. Join 7,500+ detection engineers in the community. Use code "DEW" to get started: detections.ai

24.09.2025 12:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Threats: Microsoft seizes 338 RaccoonO365 sites, domains and panels, Two teenagers charged for London transport outage from August 2024, BlackLotus Labs latest research on SystemBC, Oliver Smith TTP updates for DPRK's BeaverTail malware family

24.09.2025 12:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

* Garv Kamra's first foray into writing SIEM detections
* Jacob Zalesky first blog post ever (!) on threat hunting ideas in AWS

24.09.2025 12:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

* Ryan Tomcik on co-occurring detection ideation using composite rules in Google SecOps
* Amitai Cohen's take on effective work & task prioritization with a gaming analogy near and dear to my heart (RTS games baby!)
* Hanif Kurniawan A. helps readers detect log source outages in Wazuh

24.09.2025 12:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability power overwhelming

DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability

In this post:
* πŸ’Ž by Dirk-jan Mollema discloses a cross-tenant Azure vulnerability that gives access to any Azure tenant, with detection opportunities to boot!
www.detectionengineering.net/p/dew-130-go...

24.09.2025 12:39 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Detection Engineering Field Manual #1 - What is a Detection Engineer? Why does Detection Engineering matter to a security org?

I'm starting a new series on Detection Engineering called the Detection Field Manual. I wanted to publish < 10 minute reads on threat detection topics I've built in the field, at conferences and our interviews for candidates at Datadog.
Here's issue 1!
www.detectionengineering.net/p/detection-...

22.06.2025 18:44 πŸ‘ 9 πŸ” 1 πŸ’¬ 1 πŸ“Œ 1
Preview
Datadog Detect: Scale your Security Operations with Detection Engineering | Datadog See metrics from all of your apps, tools & services in one place with Datadog's cloud monitoring as a service solution. Try it for free.

I'm so excited to announce that Datadog Security Research is launching a FREE, fully-online, Detection Engineering focused conference called Datadog Detect!

bit.ly/datadog-detect

Our lineup is incredible with experts in the field of detection, response and threat intelligence.

10.05.2025 18:14 πŸ‘ 10 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

Found just outside Moscone North for RSA. Now I'm pumped for my talk tomorrow. #hacktheplanet

27.04.2025 21:29 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Det. Eng. Weekly #109 - I’m making a Hinge for detection engineers Your profile is a rule, an alert is a match, and a false positive is a shitty date

Detection Engineering Weekly Issue 109 is live! www.detectionengineering.net/p/det-eng-we...

09.04.2025 20:28 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Det. Eng. Weekly #108 - Can any1 in the IC add me to their Signal group? Just tryna forward some reels and feelin left out rn

Detection Engineering Weekly issue 108 is live! www.detectionengineering.net/p/det-eng-we...

02.04.2025 13:03 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

@sekoia.io FYI your TLS cert is showing invalid due to date expiration for *.sekoia.io

09.02.2025 17:44 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I love it when you guys go deep into a topic. The deepseek episode was a great example.

04.02.2025 23:10 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Weekly: 1 hour
Deep dives: 2-3 hours

04.02.2025 21:33 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Browns coming in last yet again

22.01.2025 02:40 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.

πŸŽπŸ‘Ώ The key macOS malware families of 2024: This past year saw a sharp rise in sophisticated campaigns targeting macOS users in the enterprise and the increasing adoption of cross-platform development frameworks.

20.01.2025 17:11 πŸ‘ 11 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Preview
Tracking Threat Actors with Validin | Validin Quickly identify threat actors and discover malicious infrastructure using Validin by viewing detailed descriptions on thousands of threat actors that Validin has cataloged

I’m biased, but wowβ€”it’s so refreshing to get updates that genuinely help me better track threat actors. πŸ”₯

www.validin.com/blog/threat_...

09.01.2025 16:34 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1

Bout to go wheels up!

09.01.2025 21:34 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image Post image

Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?

08.01.2025 09:48 πŸ‘ 40 πŸ” 8 πŸ’¬ 2 πŸ“Œ 1

There has been for years! Just starting to see it be more impactful

08.01.2025 02:45 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Notion Incident Management System (NIMS) | Notion Use the Template

πŸŽ‰ link and docs and details: nims-template.notion.site

07.01.2025 00:50 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Logo for Notion Incident Management System (NIMS)

Logo for Notion Incident Management System (NIMS)

πŸš€ Excited to announce the alpha release of NIMS - a Notion-based Incident Management System!

Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.

#InfoSec #DFIR #IncidentResponse #SecOps #Notion

07.01.2025 00:42 πŸ‘ 73 πŸ” 21 πŸ’¬ 4 πŸ“Œ 5

"North Korea-nexus Golang Backdoor/Stealer from Contagious Interview campaign" published by dmpdump. #ContagiousInterview, #DPRK, #CTI https://dmpdump.github.io/posts/NorthKorea_Backdoor_Stealer/

06.01.2025 11:30 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Hi wanna β€œmake plans”?

31.12.2024 15:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN

A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN

IF IT AINT EXECUTTABLE IT AINT FOR ME - dashare.zone ADMIN

18.12.2024 21:38 πŸ‘ 351 πŸ” 45 πŸ’¬ 0 πŸ“Œ 5

Read the book twice and watched the series several times. Captain Winters is one of the top 3 leaders I try to emulate

29.12.2024 18:14 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We still have a β€œpurity” problem in infosec. People want super technical resources but don’t want them to advertise anything to survive or grow their brand. They want a mold that looks like DEFCON 2005 and hate anything that looks different. Doesn’t seem very hacker to me 🀷

29.12.2024 14:06 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Even with the OPs main text, those are all great resources. There’s some actual charlatans like jonathandata1, but 95% of the people posted come from posters who seem just upset that they are not technical enough to their standards

29.12.2024 14:06 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
From the cybersecurity community on Reddit Explore this post and more from the cybersecurity community

The cybersecurity subreddit has a thread on influencers and β€œwho to avoid because of xyz”. These threads irk me because there’s no clear measurement and lots of gate keeping around who is allowed to post stuff and who isn’t. www.reddit.com/r/cybersecur...

29.12.2024 14:06 πŸ‘ 4 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I’ve been pretty sick for the last 2 weeks, but Christmas holiday has been a much needed break for rest and recovery.

Take care of yourselves people; I think stress contributed a ton to this, and being mindful and in the present has helped me out a lot.

And lots of Christmas food.

26.12.2024 16:41 πŸ‘ 7 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0