detections.ai
View and interact with detection rules shared by the community
This post is sponsored by detections.ai!
Tired of manually writing detection rules? detections.ai uses AI agents to convert threat intel into SIGMA, SPL, KQL, YARA rules automatically. Join 7,500+ detection engineers in the community. Use code "DEW" to get started: detections.ai
24.09.2025 12:39
π 0
π 0
π¬ 0
π 0
Threats: Microsoft seizes 338 RaccoonO365 sites, domains and panels, Two teenagers charged for London transport outage from August 2024, BlackLotus Labs latest research on SystemBC, Oliver Smith TTP updates for DPRK's BeaverTail malware family
24.09.2025 12:39
π 0
π 0
π¬ 1
π 0
* Garv Kamra's first foray into writing SIEM detections
* Jacob Zalesky first blog post ever (!) on threat hunting ideas in AWS
24.09.2025 12:39
π 0
π 0
π¬ 1
π 0
* Ryan Tomcik on co-occurring detection ideation using composite rules in Google SecOps
* Amitai Cohen's take on effective work & task prioritization with a gaming analogy near and dear to my heart (RTS games baby!)
* Hanif Kurniawan A. helps readers detect log source outages in Wazuh
24.09.2025 12:39
π 0
π 0
π¬ 1
π 0
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability
power overwhelming
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability
In this post:
* π by Dirk-jan Mollema discloses a cross-tenant Azure vulnerability that gives access to any Azure tenant, with detection opportunities to boot!
www.detectionengineering.net/p/dew-130-go...
24.09.2025 12:39
π 2
π 0
π¬ 1
π 0
Detection Engineering Field Manual #1 - What is a Detection Engineer?
Why does Detection Engineering matter to a security org?
I'm starting a new series on Detection Engineering called the Detection Field Manual. I wanted to publish < 10 minute reads on threat detection topics I've built in the field, at conferences and our interviews for candidates at Datadog.
Here's issue 1!
www.detectionengineering.net/p/detection-...
22.06.2025 18:44
π 9
π 1
π¬ 1
π 1
Datadog Detect: Scale your Security Operations with Detection Engineering | Datadog
See metrics from all of your apps, tools & services in one place with Datadog's cloud monitoring as a service solution. Try it for free.
I'm so excited to announce that Datadog Security Research is launching a FREE, fully-online, Detection Engineering focused conference called Datadog Detect!
bit.ly/datadog-detect
Our lineup is incredible with experts in the field of detection, response and threat intelligence.
10.05.2025 18:14
π 10
π 3
π¬ 0
π 0
Found just outside Moscone North for RSA. Now I'm pumped for my talk tomorrow. #hacktheplanet
27.04.2025 21:29
π 2
π 1
π¬ 0
π 0
@sekoia.io FYI your TLS cert is showing invalid due to date expiration for *.sekoia.io
09.02.2025 17:44
π 2
π 0
π¬ 1
π 0
I love it when you guys go deep into a topic. The deepseek episode was a great example.
04.02.2025 23:10
π 3
π 2
π¬ 0
π 0
Weekly: 1 hour
Deep dives: 2-3 hours
04.02.2025 21:33
π 2
π 0
π¬ 1
π 0
Browns coming in last yet again
22.01.2025 02:40
π 3
π 0
π¬ 0
π 0
2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise
Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.
ππΏ The key macOS malware families of 2024: This past year saw a sharp rise in sophisticated campaigns targeting macOS users in the enterprise and the increasing adoption of cross-platform development frameworks.
20.01.2025 17:11
π 11
π 4
π¬ 1
π 0
Bout to go wheels up!
09.01.2025 21:34
π 3
π 0
π¬ 1
π 0
Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?
08.01.2025 09:48
π 40
π 8
π¬ 2
π 1
There has been for years! Just starting to see it be more impactful
08.01.2025 02:45
π 4
π 0
π¬ 0
π 0
Logo for Notion Incident Management System (NIMS)
π Excited to announce the alpha release of NIMS - a Notion-based Incident Management System!
Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.
#InfoSec #DFIR #IncidentResponse #SecOps #Notion
07.01.2025 00:42
π 73
π 21
π¬ 4
π 5
"North Korea-nexus Golang Backdoor/Stealer from Contagious Interview campaign" published by dmpdump. #ContagiousInterview, #DPRK, #CTI https://dmpdump.github.io/posts/NorthKorea_Backdoor_Stealer/
06.01.2025 11:30
π 1
π 2
π¬ 0
π 0
Hi wanna βmake plansβ?
31.12.2024 15:29
π 0
π 0
π¬ 0
π 0
A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN
IF IT AINT EXECUTTABLE IT AINT FOR ME - dashare.zone ADMIN
18.12.2024 21:38
π 351
π 45
π¬ 0
π 5
Read the book twice and watched the series several times. Captain Winters is one of the top 3 leaders I try to emulate
29.12.2024 18:14
π 2
π 0
π¬ 0
π 0
We still have a βpurityβ problem in infosec. People want super technical resources but donβt want them to advertise anything to survive or grow their brand. They want a mold that looks like DEFCON 2005 and hate anything that looks different. Doesnβt seem very hacker to me π€·
29.12.2024 14:06
π 3
π 0
π¬ 1
π 0
Even with the OPs main text, those are all great resources. Thereβs some actual charlatans like jonathandata1, but 95% of the people posted come from posters who seem just upset that they are not technical enough to their standards
29.12.2024 14:06
π 2
π 0
π¬ 1
π 0
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
The cybersecurity subreddit has a thread on influencers and βwho to avoid because of xyzβ. These threads irk me because thereβs no clear measurement and lots of gate keeping around who is allowed to post stuff and who isnβt. www.reddit.com/r/cybersecur...
29.12.2024 14:06
π 4
π 0
π¬ 2
π 0
Iβve been pretty sick for the last 2 weeks, but Christmas holiday has been a much needed break for rest and recovery.
Take care of yourselves people; I think stress contributed a ton to this, and being mindful and in the present has helped me out a lot.
And lots of Christmas food.
26.12.2024 16:41
π 7
π 0
π¬ 2
π 0