Detection Engineering
-
Threat Intelligence
Detection Rules Need the Same Lifecycle as Application Code
A rule written once and never tested silently stops working when a log format changes, and nobody notices because absence…
Read More » -
Threat Intelligence
Attackers Prefer Your Own Tools Because Your Tools Are Allowed
PowerShell, WMI and certutil are signed, expected and installed everywhere, which makes signature-based detection useless against them.
Read More »