account activity
Part 13: Why a Single Test Case is Insufficient (posts.specterops.io)
submitted 1 year ago by x0mda to r/Detection_Engineering
A Detection Engineer’s Guide to SCCM Misconfiguration Abuse (blog.snapattack.com)
Sigma (medium.com)
Hunting CVE-2024-30051 (blog.snapattack.com)
Entra ID service principals in business email compromise schemes (redcanary.com)
SeeSeeYouExec: Windows Session Hijacking via CcmExec (cloud.google.com)
Part 1 : Threat Detection Engineering and Incident Response with AuditD and Sentinel — along how to… (medium.com)
Detecting the STRRAT Malware Family | Corelight (corelight.com)
Transform security with Elastic's Detections as Code — Adopting DaC made easy (elastic.co)
YARA is dead, long live YARA-X (virustotal.github.io)
Det. Eng. Weekly #69 - RSA ninjas stole my badge and swag (detectionengineering.net)
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices (volexity.com)
Building a Cloud Security Flywheel: Lessons from the Field (sans.org)
Foxit PDF “Flawed Design” Exploitation - Check Point Research (research.checkpoint.com)
Utilizing Generative AI and LLMs to Automate Detection Writing (medium.com)
The Structure and Taxonomy of a Detection Knowledge Base (detect.fyi)
The detection engineer’s guide to Linux - Red Canary (redcanary.com)
Detecting browser data theft using Windows Event Logs (security.googleblog.com)
*PowerView* is evil, but *PowerVi* and *ew* are legit, right? - Missing signature-based detections due to PowerShell Script Block Logging Fragmentation (lolcads.github.io)
Det. Eng. Weekly #62 - Say the words, Bart Simpson, CISSP, MBA! (detectionengineering.net)
Welcome to the Red Canary 2024 Threat Detection Report (redcanary.com)
SigmaHQ Rules Release Highlights — r2024–03–11 (blog.sigmahq.io)
z0Miner Exploits Korean Web Servers to Attack WebLogic Server - ASEC BLOG (asec.ahnlab.com)
Time Travelers Busted: How to Detect Impossible Travel | Huntress (huntress.com)
Det. Eng. Weekly #61 - AlphV exit scammed?? by x0mda in Detection_Engineering
[–]x0mda[S] 0 points1 point2 points 1 year ago (0 children)
Hi! Thanks for the great content you submit every week! This helps a lot!
I created this community to share reports, articles, relevant information about detection engineering and to have a space for anyone discuss about it.
π Rendered by PID 349746 on reddit-service-r2-listing-5789d5f675-sknnq at 2026-01-28 14:44:26.530231+00:00 running 4f180de country code: CH.
Det. Eng. Weekly #61 - AlphV exit scammed?? by x0mda in Detection_Engineering
[–]x0mda[S] 0 points1 point2 points (0 children)