Detection Engineering Weekly
Subscribe
Sign in
Home
Notes
Field Manual
Archive
Leaderboard
About
Latest
Top
Discussions
DEW #135 - Chaos Detection Engineering, Connecting Policy to IR playbooks & Spooky AWS Policies
spooky scary detection rules keepin' me up at night
Oct 29
•
Zack Allen
5
3
DEW #134 - Prioritizing Critical Assets, AI SOC means MORE alerts and Microsoft CoPilot Phishing
Have you tried just being 100% accurate all the time you goober?
Oct 22
•
Zack Allen
9
3
DEW #133 - Redefining Security Visibility, TTP-First Hunting & F5 breach
we should define a standard to unite all standards
Oct 16
•
Zack Allen
5
DEW #132 - Linux Rootkits Evolution, LLM Rule Evals, Oracle 0-day exploitation
༼ つ ಥ_ಥ ༽つ noo all my rootkits are obsolete ლ(ಠ益ಠლ)
Oct 8
•
Zack Allen
7
3
DEW #131 - ❄️New EDR bypass❄️, CTI Poverty, AWS Infra Canaries & Hunting in IMDS
🫂GET IN🫂CLICK🫂HUNTING🫂NEWS🫂THREAT ACTOR HARMONY🫂DRAMA🫂RULES🫂IOC JUICERS
Oct 1
•
Zack Allen
11
September 2025
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability
power overwhelming
Sep 24
•
Zack Allen
8
DEW #129 - Malicious browser extensions, npm gets pwned (again) and AI weaponizing CVEs
At least they had 2FA right?? right??????
Sep 17
•
Zack Allen
7
1
DEW #128 - AI Detection Engineering Uncertainty, 3D Threat Hunting and Salesloft Drift Shenanigans
and the Bills win season opener #gobills
Sep 10
•
Zack Allen
13
1
DEW #127: SOC Visibility Triad, Feedback loops in detection, PowerShell detection ideation
In November 2006, Windows PowerShell was created. This made a lot of people very unhappy and has widely been regarded as a bad move
Sep 3
•
Zack Allen
7
August 2025
Det. Eng. Weekly #126 - live laugh logs
every SOC should have this over their kitchen tables
Aug 27
•
Zack Allen
10
Det. Eng. Weekly #125 - I'm the Miss Rachel of Threat Detection
Uh oh that's a bad rule!
Aug 19
•
Zack Allen
16
1
Det. Eng. Weekly Issue #124 - The DEFCON hangover is real
Yall are tiring me just from all the posts and drunk texts
Aug 13
•
Zack Allen
8
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts