Skip to content

Home

This blog documents technical research, practical experiments, and lessons learned from the trenches of defensive security operations.

The content focuses on understanding attacker behavior, maximizing telemetry visibility, and building resilient detection coverage within enterprise environments.

Blog Index & Navigation

Detection Engineering

My detection workflow is based on three principles:

  • Telemetry-Grounded Implementation

    Detection capabilities must be built upon verified, available telemetry. We do not write rules for hypothetical threats that our data fabric cannot actively support or validate.

  • Hypothesis-Driven Design

    Every detection logic must stem from a concrete, testable adversary hypothesis. We detect specific behaviors and tactics, not generic anomalies.

  • Resilient Coverage over Rigid Signatures

    We prioritize identifying and closing visibility gaps across data sources (e.g., Sysmon, Security Logs, and ETW). Our goal is behavioral coverage across the detection pipeline that withstands adversary tampering and bypasses.

  • Detection Overview - Core Thinking and Strategy Framework of Detection Engineering

  • Initial Access & Delivery - Entry point and malicious payload delivery detection
  • Execution & Defense Evasion - Analysis of Malicious Execution and Defense Bypass Techniques
  • Persistence - Access control and backdoor surveillance
  • Credential Access & Network Attacks - Host and network layer credential theft detection
  • Lateral Movement & Remote Execution - Lateral movement and remote command execution tracing
  • Impact & Defense Evasion - Impact on damage and advanced defense to evade detection
  • Virtualization Escape - Research on Virtualization Escape and Container Security

Telemetry & Artifacts

  • Event Logs - In-depth study of Windows Security Event Logs, Sysmon, and advanced telemetry

Malware Analysis

  • Malware Analysis - Malware analysis, behavioral profiling, and IOC threat indicator extraction

Hands-on Labs & CTF (Hack The Box)

Resources

  • Tools - A list of tools and script resources used in threat hunting, detection engineering, and forensic analysis.