Curated news and original thought pieces on detection engineering — short summaries that grab the key words and value from each author.
Short, high-signal articles and news summarized — at a frequency of your choosing. One click to subscribe.
Elastic Security Labs
Detect the initial infection chain with `cmd /c curl ... | cmd.exe` and later stages like `ClipCursor`, UAC loops, or kiosk mode browser launches.
Krebs on Security
Understanding this actor's brazen exploit acquisition model helps detection teams monitor and hunt for activities related to the sale and development of new vulnerabilities rather than just known malware.
Google Cloud — Security & Identity
Highlights emerging security domains like EDR for AI agents and the push toward quantum-resistant infrastructure.
Google Cloud — Security & Identity
Automates the prioritization of which exposures matter most by correlating known exploits against your specific environment.
Google Cloud — Threat Intelligence
Monitor Event ID 385 to detect configuration drift and enforce automated certificate management for safer key lifecycle handling.
Google Cloud — Security & Identity
Detection engineers can monitor the entire trust chain from certificate validation and JWT issuance down to granular NATS subject permissions rather than chasing leaked keys.
Krebs on Security
Understanding how compromised home networks are used as exit nodes helps engineers model adversary obfuscation and identify indicators from NetNut's SDK/backend infra.
Google Cloud — Threat Intelligence
Detection engineers can use shared indicators for NetNut's SDKs and C2 to identify malicious proxy activity and compromised home devices used as exit nodes.
Elastic Security Labs
Offload routine triage to code so analysts only touch high-signal, non-deterministic investigations.
Google Cloud — Security & Identity
Validates Google Cloud’s security posture through independent audit, reducing compliance risk for public sector migrations.
Google Cloud — Security & Identity
Use third-party validation and quantified business metrics to justify security investments and resource allocation at the executive level.
Alex Rivera — Blue Team Notes
Most broken SIGMA-to-Elastic conversions come down to three fixable causes: mismatched field mappings, ignored log-source scoping, and skipping post-conversion tuning against real data.
Red Canary
Offload high-volume triage to an automated pipeline so analysts can focus on nuanced threat hunting instead of manual classification.
Google Cloud — Security & Identity
Demonstrates how agentic workflows can automate high-volume tasks like security review, vulnerability verification, and patch generation at scale.
The DFIR Report
This case highlights a multi-stage campaign from initial SEO lure to credential theft and ransomware deployment — useful for building detections across the full kill chain (sideloading, persistence, lateral movement).
Google Cloud — Threat Intelligence
Understanding these evolving tactics and the use of AI helps defenders anticipate wider targeting beyond Ukraine and build more comprehensive detection strategies.
Arjun G. Raman — Babels
Babels exists to make high-quality detection engineering more accessible — pairing open-source tooling with AI-assisted workflows so practitioners can convert, validate, and deploy detections faster.
Google Cloud — Security & Identity
VPC Service Controls act as a critical safety net by blocking data exfiltration at the API layer even when an agent possesses valid IAM credentials.
Google Cloud — Threat Intelligence
Detection can focus on inter-process communication via WM_COPYDATA messages and the use of websocket-sharp for C2 tunneling.