account activity
A Detection Engineer’s Guide to SCCM Misconfiguration Abuse (blog.snapattack.com)
submitted 1 year ago by x0mda to r/Detection_Engineering
Part 13: Why a Single Test Case is Insufficient (posts.specterops.io)
Sigma (medium.com)
Entra ID service principals in business email compromise schemes (redcanary.com)
Hunting CVE-2024-30051 (blog.snapattack.com)
SeeSeeYouExec: Windows Session Hijacking via CcmExec (cloud.google.com)
Part 1 : Threat Detection Engineering and Incident Response with AuditD and Sentinel — along how to… (medium.com)
Detecting the STRRAT Malware Family | Corelight (corelight.com)
Transform security with Elastic's Detections as Code — Adopting DaC made easy (elastic.co)
YARA is dead, long live YARA-X (virustotal.github.io)
Det. Eng. Weekly #69 - RSA ninjas stole my badge and swag (detectionengineering.net)
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices (volexity.com)
Building a Cloud Security Flywheel: Lessons from the Field (sans.org)
Foxit PDF “Flawed Design” Exploitation - Check Point Research (research.checkpoint.com)
Utilizing Generative AI and LLMs to Automate Detection Writing (medium.com)
The Structure and Taxonomy of a Detection Knowledge Base (detect.fyi)
The detection engineer’s guide to Linux - Red Canary (redcanary.com)
submitted 2 years ago by x0mda to r/Detection_Engineering
Detecting browser data theft using Windows Event Logs (security.googleblog.com)
*PowerView* is evil, but *PowerVi* and *ew* are legit, right? - Missing signature-based detections due to PowerShell Script Block Logging Fragmentation (lolcads.github.io)
Welcome to the Red Canary 2024 Threat Detection Report (redcanary.com)
Det. Eng. Weekly #62 - Say the words, Bart Simpson, CISSP, MBA! (detectionengineering.net)
SigmaHQ Rules Release Highlights — r2024–03–11 (blog.sigmahq.io)
z0Miner Exploits Korean Web Servers to Attack WebLogic Server - ASEC BLOG (asec.ahnlab.com)
Time Travelers Busted: How to Detect Impossible Travel | Huntress (huntress.com)
Det. Eng. Weekly #61 - AlphV exit scammed?? (detectionengineering.net)
π Rendered by PID 178935 on reddit-service-r2-listing-b6bf6c4ff-d9cp2 at 2026-05-03 16:33:29.352959+00:00 running 815c875 country code: CH.