home.social

#detectionengineering โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #detectionengineering, aggregated by home.social.

fetched live
  1. ๐Ÿ›ก๏ธ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    โ€ข Suricata / suricata-update
    โ€ข OPNsense
    โ€ข pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    ๐Ÿ“– OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide โ€” Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  2. ๐Ÿ›ก๏ธ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    โ€ข Suricata / suricata-update
    โ€ข OPNsense
    โ€ข pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    ๐Ÿ“– OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide โ€” Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  3. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    โ€ข 6,007,331 HTTP signatures
    โ€ข 243,098 TLS signatures
    โ€ข 243,098 DNS signatures
    โ€ข 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds โ†’ IOC processing โ†’ Rule generation โ†’ Suricata โ†’ Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  4. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    โ€ข 6,007,331 HTTP signatures
    โ€ข 243,098 TLS signatures
    โ€ข 243,098 DNS signatures
    โ€ข 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds โ†’ IOC processing โ†’ Rule generation โ†’ Suricata โ†’ Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  5. ๐Ÿ“ข Come join us in Atlanta, GA November 13-14 at Monday Night Brewing - The Grove, for #DEATHCon 2026 on-site! ๐Ÿ“ข

    We'll have a ton of excellent workshops and interesting environments to explore, focusing on #threathunting and #detectionengineering! ๐Ÿ” ๐Ÿน

    Meet fellow practitioners, learn something new, and enjoy some great food and beverages in a relaxed, friendly setting! ๐Ÿค ๐Ÿฅช

    simpletix.com/e/deathcon-atlan

  6. ๐Ÿ“ข Come join us in Atlanta, GA November 13-14 at Monday Night Brewing - The Grove, for #DEATHCon 2026 on-site! ๐Ÿ“ข

    We'll have a ton of excellent workshops and interesting environments to explore, focusing on #threathunting and #detectionengineering! ๐Ÿ” ๐Ÿน

    Meet fellow practitioners, learn something new, and enjoy some great food and beverages in a relaxed, friendly setting! ๐Ÿค ๐Ÿฅช

    simpletix.com/e/deathcon-atlan

  7. Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick.

    DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting.

    deathcon.io/tickets.html

    #deathcon #threathunting #detectionengineering #conference

  8. Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with OtterCookie/InvisibleFerret. Regardless, extraction of TTPs is super easy when the source code is available and great for folks who want an introduction into detection engineering and/or threat hunting.

    For example, Overlord RAT ships with default self-signed certificates/port configurations. While advanced adversaries will obviously alter these settings, many groups wonโ€™t, including UNK_DeadDrop. This makes developing a baseline detection within Censys/Shodan/FOFA trivial for monitoring. The Censys query in the screenshot is rudimentary, but you get the idea. Start with low-hanging fruit and tune your queries to hunt for advanced adversaries who might be using more bespoke Overlord configurations. Once found, ingest and retro-hunt the IOCs in your environment. Overlord clients will establish C2 communications with these servers.

    proofpoint.com/us/blog/threat-
    github.com/vxaboveground/Overl

    #overlord #unk_deaddrop #RAT #detectionengineering #threathunting #cti #threatintel

  9. New post: Detecting Misuse with the Claude Compliance API ๐Ÿ”

    Mapping the Compliance API feed to your SIEM gets you IAM and access detections โ€œfor freeโ€, but the real AI threats live in the message content: prompt injection, jailbreaks, exfiltration prep, shadow data flow.

    So I built a prefilter โ†’ LLM judge โ†’ SIEM pipeline to catch them, with a working repo + Sigma rules to run offline.

    papermtn.co.uk/detecting-misus

    #infosec #DetectionEngineering #LLMSecurity #AI #blueteam

  10. New post: Detecting Misuse with the Claude Compliance API ๐Ÿ”

    Mapping the Compliance API feed to your SIEM gets you IAM and access detections โ€œfor freeโ€, but the real AI threats live in the message content: prompt injection, jailbreaks, exfiltration prep, shadow data flow.

    So I built a prefilter โ†’ LLM judge โ†’ SIEM pipeline to catch them, with a working repo + Sigma rules to run offline.

    papermtn.co.uk/detecting-misus

    #infosec #DetectionEngineering #LLMSecurity #AI #blueteam

  11. Detection engineers aren't being displaced by autonomous SOC capabilities. They're being asked to shift perspective
    .
    Not: does this rule fire correctly?
    But: which signals are trustworthy enough for the system to act on without me? What confidence threshold separates automatic containment from escalation?

    Same deep attacker expertise. Applied to a new layer of decisions.

    gethumming.io
    #ITDR #SecurityOps #DetectionEngineering #CyberSecurity

  12. Has anyone been able to successfully replicate copying and pasting ClickFix/TerminalFix/*Fix commands into macOS Terminal to trigger this new-fangled malware warning? I have attempted numerous commands, from base64-encoded content to osascripts mimicking macOS infostealer prompts to cURL commands downloading remote content. I even replicated the command documented in the Toms Guide article using the same tool in the same browser and it ran flawlessly in Terminal with no popup. And yes, Iโ€™m running Tahoe 26.4 on an M3. Iโ€™d like to think this would be a useful โ€˜stop-and-thinkโ€™ mitigation but I canโ€™t even consistently trigger it. And, per usual, Apple is tight-lipped on HOW they are detecting malicious commands so itโ€™s likely to remain a black box mitigation. And yeah, I get it, the end user can just click right through the warning via a sneaky social engineering prompt. My goal was to try and build out detection logic to ID when a user gets hit with a prompt so I can at least investigate what the user tried to do and dig deeper into the threat. Since theoretically the user wonโ€™t run the command, it wonโ€™t get logged in SIEM/EDR tools. I need to rely on other mechanisms for detecting the paste event.

    tomsguide.com/computing/online

    #macos #clickfix #terminalfix #threatintel #pastejacking #detectionengineering #threathunting

  13. CVE-2026-21902 represents a high-impact infrastructure exposure.

    Affected platform: Junos OS Evolved on PTX series routers.

    Attack vector: Unauthenticated network access.
    Privilege level: Root execution.
    Service: On-Box Anomaly Detection, enabled by default.

    Strategic risk:
    โ€ข Traffic interception capability
    โ€ข Policy manipulation
    โ€ข Controller redirection
    โ€ข Lateral pivoting
    โ€ข Long-term foothold persistence
    Although no exploitation has been observed, historically, high-performance routing infrastructure is a prime target due to its control-plane visibility and network centrality.

    Recommended actions:
    โ€“ Immediate patch validation
    โ€“ Control-plane traffic monitoring
    โ€“ Service exposure review
    โ€“ Network segmentation validation
    โ€“ Threat hunting for anomalous routing behavior
    Are infrastructure devices integrated into your continuous detection engineering pipeline?

    Source: securityweek.com/juniper-netwo

    Engage below.
    Follow TechNadu for high-signal vulnerability intelligence.
    Repost to strengthen security awareness.

    #Infosec #CVE2026 #Juniper #RouterSecurity #CriticalInfrastructure #ThreatModeling #DetectionEngineering #NetworkDefense #ZeroTrustArchitecture #CyberRisk #SecurityOperations #VulnerabilityManagement

  14. APT37โ€™s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    โ€ข LNK-based initial execution
    โ€ข Embedded PowerShell payload extraction
    โ€ข Ruby interpreter abuse (v3.3.0)
    โ€ข Scheduled task persistence (5-minute interval)
    โ€ข USB-based covert bidirectional C2
    โ€ข Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    โ€“ Command staging offline
    โ€“ Data exfiltration without internet access
    โ€“ Lateral spread across isolated systems
    โ€“ Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection โ€” including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  15. APT37โ€™s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    โ€ข LNK-based initial execution
    โ€ข Embedded PowerShell payload extraction
    โ€ข Ruby interpreter abuse (v3.3.0)
    โ€ข Scheduled task persistence (5-minute interval)
    โ€ข USB-based covert bidirectional C2
    โ€ข Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    โ€“ Command staging offline
    โ€“ Data exfiltration without internet access
    โ€“ Lateral spread across isolated systems
    โ€“ Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection โ€” including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  16. Weโ€™re looking for a Detection Engineer to build and maintain detection rules using the detection-as-code principle (with Sigma!). If youโ€™re into turning threat intelligence data into actionable alerts, we want to hear from you! ๐Ÿš€

    #detectionengineering

    cert.europa.eu/vacancies/it-se

  17. ๐Ÿ‹๏ธ ๐—ก๐—ผ๐—ฟ๐˜๐—ต๐—ฆ๐—ฒ๐—ฐ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ ๐—™๐—ผ๐—ฟ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€/๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด๐˜€ (9/12): "Advanced Detection Engineering in the Enterprise" ๐—ฝ๐—ฎ๐—ฟ/๐—ฏ๐˜† Olaf Hartong & Rogier Boon (FalconForce)

    ๐Ÿ“… Dates: May 11, 12 and 13, 2026 (3 days)
    ๐Ÿ“Š Difficulty: Medium
    ๐Ÿ–ฅ๏ธ Mode: On-Site

    Description: "๐˜๐˜ข๐˜ญ๐˜ค๐˜ฐ๐˜ฏ๐˜๐˜ฐ๐˜ณ๐˜ค๐˜ฆ ๐˜ฅ๐˜ฆ๐˜ท๐˜ฆ๐˜ญ๐˜ฐ๐˜ฑ๐˜ฆ๐˜ฅ ๐˜ข ๐˜ด๐˜ฑ๐˜ฆ๐˜ค๐˜ช๐˜ข๐˜ญ๐˜ช๐˜ด๐˜ต ๐˜ธ๐˜ฐ๐˜ณ๐˜ฌ๐˜ด๐˜ฉ๐˜ฐ๐˜ฑ ๐˜ง๐˜ฐ๐˜ณ ๐˜ด๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ ๐˜ฑ๐˜ณ๐˜ฐ๐˜ง๐˜ฆ๐˜ด๐˜ด๐˜ช๐˜ฐ๐˜ฏ๐˜ข๐˜ญ๐˜ด ๐˜ต๐˜ฐ ๐˜ฉ๐˜ฆ๐˜ญ๐˜ฑ ๐˜ต๐˜ข๐˜ฌ๐˜ช๐˜ฏ๐˜จ ๐˜ต๐˜ฉ๐˜ฆ๐˜ช๐˜ณ ๐˜ฅ๐˜ฆ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ฆ๐˜ฏ๐˜จ๐˜ช๐˜ฏ๐˜ฆ๐˜ฆ๐˜ณ๐˜ช๐˜ฏ๐˜จ ๐˜ค๐˜ข๐˜ฑ๐˜ข๐˜ฃ๐˜ช๐˜ญ๐˜ช๐˜ต๐˜ช๐˜ฆ๐˜ด ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฏ๐˜ฆ๐˜น๐˜ต ๐˜ญ๐˜ฆ๐˜ท๐˜ฆ๐˜ญ. ๐˜ˆ๐˜ฏ ๐˜ถ๐˜ญ๐˜ต๐˜ช๐˜ฎ๐˜ข๐˜ต๐˜ฆ ๐˜ฅ๐˜ฆ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ฆ๐˜ฏ๐˜จ๐˜ช๐˜ฏ๐˜ฆ๐˜ฆ๐˜ณ๐˜ช๐˜ฏ๐˜จ ๐˜ญ๐˜ฆ๐˜ข๐˜ณ๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ฆ๐˜น๐˜ฑ๐˜ฆ๐˜ณ๐˜ช๐˜ฆ๐˜ฏ๐˜ค๐˜ฆ ๐˜ธ๐˜ช๐˜ต๐˜ฉ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฐ๐˜ฑ๐˜ฑ๐˜ฐ๐˜ณ๐˜ต๐˜ถ๐˜ฏ๐˜ช๐˜ต๐˜บ ๐˜ต๐˜ฐ ๐˜จ๐˜ฐ ๐˜ข๐˜ญ๐˜ญ-๐˜ช๐˜ฏ ๐˜ธ๐˜ช๐˜ต๐˜ฉ ๐˜ณ๐˜ฆ๐˜ข๐˜ญ-๐˜ญ๐˜ช๐˜ง๐˜ฆ, ๐˜ฉ๐˜ข๐˜ฏ๐˜ฅ๐˜ด-๐˜ฐ๐˜ฏ ๐˜ญ๐˜ข๐˜ฃ ๐˜ฆ๐˜น๐˜ฆ๐˜ณ๐˜ค๐˜ช๐˜ด๐˜ฆ๐˜ด. ๐˜›๐˜ฉ๐˜ฆ ๐˜ต๐˜ณ๐˜ข๐˜ช๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ค๐˜ฐ๐˜ท๐˜ฆ๐˜ณ๐˜ด ๐˜ข ๐˜ง๐˜ถ๐˜ญ๐˜ญ, ๐˜ณ๐˜ฆ๐˜ข๐˜ญ๐˜ช๐˜ด๐˜ต๐˜ช๐˜ค ๐˜ข๐˜ต๐˜ต๐˜ข๐˜ค๐˜ฌ๐˜ฆ๐˜ณ ๐˜ด๐˜ค๐˜ฆ๐˜ฏ๐˜ข๐˜ณ๐˜ช๐˜ฐ ๐˜ช๐˜ฏ ๐˜ข๐˜ฏ ๐˜ฆ๐˜ฏ๐˜ต๐˜ฆ๐˜ณ๐˜ฑ๐˜ณ๐˜ช๐˜ด๐˜ฆ ๐˜ฆ๐˜ฏ๐˜ท๐˜ช๐˜ณ๐˜ฐ๐˜ฏ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต: ๐˜ง๐˜ณ๐˜ฐ๐˜ฎ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฆ๐˜ฏ๐˜ฅ๐˜ฑ๐˜ฐ๐˜ช๐˜ฏ๐˜ต, ๐˜ต๐˜ฉ๐˜ณ๐˜ฐ๐˜ถ๐˜จ๐˜ฉ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ˆ๐˜ค๐˜ต๐˜ช๐˜ท๐˜ฆ ๐˜‹๐˜ช๐˜ณ๐˜ฆ๐˜ค๐˜ต๐˜ฐ๐˜ณ๐˜บ ๐˜ข๐˜ฏ๐˜ฅ ๐˜ช๐˜ฏ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ค๐˜ญ๐˜ฐ๐˜ถ๐˜ฅ ๐˜ฆ๐˜ฏ๐˜ท๐˜ช๐˜ณ๐˜ฐ๐˜ฏ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต.

    ๐˜›๐˜ฉ๐˜ช๐˜ด ๐˜ต๐˜ณ๐˜ข๐˜ช๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ช๐˜ด ๐˜ญ๐˜ฆ๐˜ฅ ๐˜ฃ๐˜บ ๐˜ฆ๐˜น๐˜ฑ๐˜ฆ๐˜ณ๐˜ช๐˜ฆ๐˜ฏ๐˜ค๐˜ฆ๐˜ฅ ๐˜ช๐˜ฏ๐˜ด๐˜ต๐˜ณ๐˜ถ๐˜ค๐˜ต๐˜ฐ๐˜ณ๐˜ด ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ต๐˜ฆ๐˜ข๐˜ค๐˜ฉ ๐˜ด๐˜ต๐˜ถ๐˜ฅ๐˜ฆ๐˜ฏ๐˜ต๐˜ด ๐˜ต๐˜ฐ:
    ๐˜œ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ณ๐˜ด๐˜ต๐˜ข๐˜ฏ๐˜ฅ ๐˜ฉ๐˜ฐ๐˜ธ ๐˜ต๐˜ฐ ๐˜ณ๐˜ฆ๐˜ด๐˜ฆ๐˜ข๐˜ณ๐˜ค๐˜ฉ ๐˜ข๐˜ฏ ๐˜ข๐˜ต๐˜ต๐˜ข๐˜ค๐˜ฌ๐˜ฆ๐˜ณ ๐˜ต๐˜ฆ๐˜ค๐˜ฉ๐˜ฏ๐˜ช๐˜ฒ๐˜ถ๐˜ฆ ๐˜ถ๐˜ด๐˜ฆ๐˜ฅ ๐˜ช๐˜ฏ ๐˜ค๐˜ฐ๐˜ณ๐˜ฑ๐˜ฐ๐˜ณ๐˜ข๐˜ต๐˜ฆ ๐˜ฆ๐˜ฏ๐˜ท๐˜ช๐˜ณ๐˜ฐ๐˜ฏ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต๐˜ด. ๐˜‰๐˜ถ๐˜ช๐˜ญ๐˜ฅ ๐˜ณ๐˜ฆ๐˜ด๐˜ช๐˜ญ๐˜ช๐˜ฆ๐˜ฏ๐˜ต ๐˜ฅ๐˜ฆ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜ข๐˜ณ๐˜ฆ ๐˜ฉ๐˜ข๐˜ณ๐˜ฅ๐˜ฆ๐˜ณ ๐˜ต๐˜ฐ ๐˜ฆ๐˜ท๐˜ข๐˜ฅ๐˜ฆ ๐˜ฃ๐˜บ ๐˜ข๐˜ฏ ๐˜ข๐˜ต๐˜ต๐˜ข๐˜ค๐˜ฌ๐˜ฆ๐˜ณ. ๐˜๐˜ข๐˜ญ๐˜ช๐˜ฅ๐˜ข๐˜ต๐˜ฆ ๐˜ต๐˜ฉ๐˜ฆ๐˜ช๐˜ณ ๐˜ฅ๐˜ฆ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ด ๐˜ต๐˜ฐ ๐˜ฎ๐˜ข๐˜ฌ๐˜ฆ ๐˜ด๐˜ถ๐˜ณ๐˜ฆ ๐˜ต๐˜ฉ๐˜ฆ๐˜บ ๐˜ฌ๐˜ฆ๐˜ฆ๐˜ฑ ๐˜ง๐˜ถ๐˜ฏ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ข๐˜ด ๐˜ช๐˜ฏ๐˜ต๐˜ฆ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ฅ. ๐˜›๐˜ฉ๐˜ฆ ๐˜ต๐˜ณ๐˜ข๐˜ช๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ง๐˜ฐ๐˜ค๐˜ถ๐˜ด๐˜ฆ๐˜ด ๐˜ฐ๐˜ฏ ๐˜”๐˜ช๐˜ค๐˜ณ๐˜ฐ๐˜ด๐˜ฐ๐˜ง๐˜ต ๐˜š๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ฏ๐˜ฆ๐˜ญ ๐˜ข๐˜ฏ๐˜ฅ ๐˜‹๐˜ฆ๐˜ง๐˜ฆ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ณ ๐˜Ÿ๐˜‹๐˜™, ๐˜ฃ๐˜ถ๐˜ต ๐˜ค๐˜ฐ๐˜ฏ๐˜ค๐˜ฆ๐˜ฑ๐˜ต๐˜ด ๐˜ค๐˜ข๐˜ฏ ๐˜ฃ๐˜ฆ ๐˜ข๐˜ฑ๐˜ฑ๐˜ญ๐˜ช๐˜ฆ๐˜ฅ ๐˜ต๐˜ฐ ๐˜ฐ๐˜ต๐˜ฉ๐˜ฆ๐˜ณ ๐˜ด๐˜ต๐˜ข๐˜ค๐˜ฌ๐˜ด ๐˜ข๐˜ด ๐˜ธ๐˜ฆ๐˜ญ๐˜ญ."

    About the trainers:
    Olaf Hartong has a vast experience in digital security, specialized in security operations, detection engineering and threat hunting. Olaf has extensive knowledge of different monitoring platforms, in particular the Microsoft Defender XDR and Sentinel stack. He presents on well-known security conferences, such as BlackHat, Defcon, WWHF, BRUcon, SOcon, NorthSec, Insomni'hack and MITRE ATT&CKcon. Olaf is the author of ThreatHunting for Splunk, ATTACK datamap, FalconHound, and Sysmon-modular tools.

    Rogier Boon has over 20 years experience as both a security consultant and in-house technical specialist. Throughout his career, Rogier had roles as offensive specialist and blue teamer (TIER2/3 SOC, incident response, detection engineer). Rogier brings extensive experience working in various high-tech environments and researching a multitude of technologies. Rogier facilitated at Black Hat US and various private trainings sessions for in-house SOC teams.

    ๐Ÿ”— Save Your Spot: nsec.io/training/2026-advanced

    #NorthSec #cybersecurity #detectionengineering #infosec #blueeteam