Home
This blog documents technical research, practical experiments, and lessons learned from the trenches of defensive security operations.
The content focuses on understanding attacker behavior, maximizing telemetry visibility, and building resilient detection coverage within enterprise environments.
Blog Index & Navigation¶
Detection Engineering¶
My detection workflow is based on three principles:
-
Telemetry-Grounded Implementation
Detection capabilities must be built upon verified, available telemetry. We do not write rules for hypothetical threats that our data fabric cannot actively support or validate.
-
Hypothesis-Driven Design
Every detection logic must stem from a concrete, testable adversary hypothesis. We detect specific behaviors and tactics, not generic anomalies.
-
Resilient Coverage over Rigid Signatures
We prioritize identifying and closing visibility gaps across data sources (e.g., Sysmon, Security Logs, and ETW). Our goal is behavioral coverage across the detection pipeline that withstands adversary tampering and bypasses.
-
Detection Overview - Core Thinking and Strategy Framework of Detection Engineering
- Initial Access & Delivery - Entry point and malicious payload delivery detection
- Execution & Defense Evasion - Analysis of Malicious Execution and Defense Bypass Techniques
- Persistence - Access control and backdoor surveillance
- Credential Access & Network Attacks - Host and network layer credential theft detection
- Lateral Movement & Remote Execution - Lateral movement and remote command execution tracing
- Impact & Defense Evasion - Impact on damage and advanced defense to evade detection
- Virtualization Escape - Research on Virtualization Escape and Container Security
Telemetry & Artifacts¶
- Event Logs - In-depth study of Windows Security Event Logs, Sysmon, and advanced telemetry
Malware Analysis¶
- Malware Analysis - Malware analysis, behavioral profiling, and IOC threat indicator extraction
Hands-on Labs & CTF (Hack The Box)¶
- HTB Writeups
- Machines: Bashed | Devel | Keeper | Legacy | Nibbles | OpenAdmin | Optimum
- Sherlocks: Campfire-1
Resources¶
- Tools - A list of tools and script resources used in threat hunting, detection engineering, and forensic analysis.