Sign in

techy

@techy.detectionengineering.net
1.6K followers 408 following 70 posts

Creator of Detection Engineering Weekly (detectionengineering.net), Sec Research/Intel/Detection @ Datadog

PostsRepliesMedia
techy @techy.detectionengineering.net · 24/09/2025
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability In this post: * 💎 by Dirk-jan Mollema discloses a cross-tenant Azure vulnerability that gives access to any Azure tenant, with detection opportunities to boot! www.detectionengineering.net/p/dew-130-go...
detectionengineering.net
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability
power overwhelming
120
techy @techy.detectionengineering.net · 22/06/2025
I'm starting a new series on Detection Engineering called the Detection Field Manual. I wanted to publish < 10 minute reads on threat detection topics I've built in the field, at conferences and our interviews for candidates at Datadog. Here's issue 1! www.detectionengineering.net/p/detection-...
detectionengineering.net
Detection Engineering Field Manual #1 - What is a Detection Engineer?
Why does Detection Engineering matter to a security org?
191
techy @techy.detectionengineering.net · 10/05/2025
I'm so excited to announce that Datadog Security Research is launching a FREE, fully-online, Detection Engineering focused conference called Datadog Detect! bit.ly/datadog-detect Our lineup is incredible with experts in the field of detection, response and threat intelligence.
bit.ly
Datadog Detect: Scale your Security Operations with Detection Engineering | Datadog
See metrics from all of your apps, tools & services in one place with Datadog's cloud monitoring as a service solution. Try it for free.
0103
techy @techy.detectionengineering.net · 27/04/2025
Found just outside Moscone North for RSA. Now I'm pumped for my talk tomorrow. #hacktheplanet
021
techy @techy.detectionengineering.net · 09/04/2025
Detection Engineering Weekly Issue 109 is live! www.detectionengineering.net/p/det-eng-we...
detectionengineering.net
Det. Eng. Weekly #109 - I’m making a Hinge for detection engineers
Your profile is a rule, an alert is a match, and a false positive is a shitty date
042
techy @techy.detectionengineering.net · 02/04/2025
Detection Engineering Weekly issue 108 is live! www.detectionengineering.net/p/det-eng-we...
detectionengineering.net
Det. Eng. Weekly #108 - Can any1 in the IC add me to their Signal group?
Just tryna forward some reels and feelin left out rn
040
techy @techy.detectionengineering.net · 09/02/2025
@sekoia.io FYI your TLS cert is showing invalid due to date expiration for *.sekoia.io
120
Reposted by techy
SentinelOne @sentinelone.com · 20/01/2025
🍎👿 The key macOS malware families of 2024: This past year saw a sharp rise in sophisticated campaigns targeting macOS users in the enterprise and the increasing adoption of cross-platform development frameworks.
s1.ai
2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise
Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.
1114
Reposted by techy
Tom Hegel @hegel.bsky.social · 09/01/2025
I’m biased, but wow—it’s so refreshing to get updates that genuinely help me better track threat actors. 🔥 www.validin.com/blog/threat_...
validin.com
Tracking Threat Actors with Validin | Validin
Quickly identify threat actors and discover malicious infrastructure using Validin by viewing detailed descriptions on thousands of threat actors that Validin has cataloged
0113
Reposted by techy
6mile @6mile.githax.com · 08/01/2025
Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?
2408
Reposted by techy
Whitney Champion 🍪 @whit.zip · 07/01/2025
🎉 link and docs and details: nims-template.notion.site
nims-template.notion.site
Notion Incident Management System (NIMS) | Notion
Use the Template
051
Reposted by techy
Eric Capuano @eric.zip · 07/01/2025
🚀 Excited to announce the alpha release of NIMS - a Notion-based Incident Management System! Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features. #InfoSec #DFIR #IncidentResponse #SecOps #Notion
Logo for Notion Incident Management System (NIMS)
47321
Reposted by techy
lazarusholic @lazarusholic.bsky.social · 06/01/2025
"North Korea-nexus Golang Backdoor/Stealer from Contagious Interview campaign" published by dmpdump. #ContagiousInterview, #DPRK, #CTI dmpdump.github.io/posts/NorthKorea_…
012
Reposted by techy
da share z0ne @dasharez0ne.bsky.social · 18/12/2024
IF IT AINT EXECUTTABLE IT AINT FOR ME - dashare.zone ADMIN
A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN
034444
techy @techy.detectionengineering.net · 29/12/2024
The cybersecurity subreddit has a thread on influencers and “who to avoid because of xyz”. These threads irk me because there’s no clear measurement and lots of gate keeping around who is allowed to post stuff and who isn’t. www.reddit.com/r/cybersecur...
reddit.com
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
240
techy @techy.detectionengineering.net · 26/12/2024
I’ve been pretty sick for the last 2 weeks, but Christmas holiday has been a much needed break for rest and recovery. Take care of yourselves people; I think stress contributed a ton to this, and being mindful and in the present has helped me out a lot. And lots of Christmas food.
270
techy @techy.detectionengineering.net · 22/12/2024
telling chatgpt my editor in a very blunt and snarky way, as all vim users do
010
Reposted by techy
Filippo Valsorda @filippo.abyssdomain.expert · 22/12/2024
The TLS Protocol Version 1.0 RFC, January 1999, in ugly meme form.

Top text:
I am not a toy
I am not a Christmas present
I am a 30+ years commitment

Bottom text:
Please think hard before you give someone
an Internet standard this Christmas
61100213
techy @techy.detectionengineering.net · 17/12/2024
Today is not a good day. Our dog needed a vet visit because he was weak and not eating. Turns out he had blood and fluid throughout his abdomen due to cancer. He was an amazing friend and family member, and tomorrow’s issue will be somber but commemorative with lots of pupper pics. Hug your dogs!
6210
Reposted by techy
Chris Farris @jcfarris.bsky.social · 17/12/2024
You've got to be a total wanker to name a law after yourself, and guess what! www.chrisfarris.com/post/three-l...
chrisfarris.com
Farris's Three Laws of Auto Remediation - Chris Farris
In this post, I present three laws of Cloud Security Robotics with homage to a SciFi great.
001
Reposted by techy
derek guy @dieworkwear.bsky.social · 15/12/2024
love these looks from Proper Cloth's new lookbook titled "New Ivy." even the grey shetland knit with black jeans and small dress watch looks great.
A man wears a taupe glen check Shetland tweed sport coat with a light blue dress shirt and mid-gray worsted trousers. he has a black belt, black loafers, and black watch strap carrying a silver dress watch. He also has a bit of silver jewelry in the form of necklaces and rings.A man wears a olive herringbone tweed sport coat with white jeans and a dark green button-up shirt. He's also wearing a bit of gold jewelry in the form of rings and bracelets, as well as a black watch strap carrying a dress watchA man wears a brown tweed sport coat with flapped patch pockets. It's paired with an ecru button-up shirt, tan chinos, brown belt, white ribbed tank, and silver necklacesA man wears a gray Shetland sweater with black jeans. He also has some rings, bracelets, and a small silver dress watch on a black leather watch strap.
1125430235
Reposted by techy
Catalin Cimpanu @campuscodi.risky.biz · 10/12/2024
DeFi platform Radiant Capital says North Korean hackers were behind the theft of over $50 million worth of assets from its servers in October this year. Radiant says it was hacked after an employee opened a malicious file received from a former contractor via Telegram: medium.com/@RadiantCapi...
medium.com
Radiant Capital Incident Update
2024–12–06
0104
Reposted by techy
netbiosX @netbiosx.bsky.social · 08/12/2024
github.com
GitHub - JoelGMSec/Invoke-Stealth: Simple & Powerful PowerShell Script Obfuscator
Simple & Powerful PowerShell Script Obfuscator. Contribute to JoelGMSec/Invoke-Stealth development by creating an account on GitHub.
172
Reposted by techy
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/12/2024
zizmor would have caught the Ultralytics workflow vulnerability blog.yossarian.net/2024/12/06/zizmo… #security #oss
2177
Reposted by techy
Ryan Naraine @ryanaraine.bsky.social · 07/12/2024
NEW pod alert! Turla caught stealing from a Pakistani APT, fourth-party espionage, threat actor attribution. Plus, a Monokle-like spyware finding, Salt Typhoon disinfections and Romania's election crisis over Russian interference via TikTok. @craiu.bsky.social @jags.bsky.social
185
Reposted by techy
Security Cryptography Whatever @scwpod.bsky.social · 07/12/2024
NEW EPISODE! Our esteemed guests @justinschuh.com and @matthewdgreen.bsky.social joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or 'just' a major fuckup: securitycryptographywhatever.com/2024/12/07/d... www.youtube.com/watch?v=i0eo...
youtube.com
Dual_EC_DRBG with Justin Schuh and Matthew Green
YouTube video by Security Cryptography Whatever
62714
techy @techy.detectionengineering.net · 07/12/2024
Ultralytics, a python package with close to 6.4 million downloads per month, was backdoored to run a cryptominer. Running theory from the reported GitHub issue is a GitHub action injection attack, but theres also evidence that the malicious code was published directly via PyPi and skipped CI/CD
1104
techy @techy.detectionengineering.net · 07/12/2024
First time I’ve seen a successful arrest and plea of a large crypto jacking campaign. Nebraska man leveraged stolen cloud resources to mine crypto for 3.5 million www.justice.gov/usao-edny/pr...
justice.gov
Nebraska Man Pleads Guilty in Multi-Million Dollar “Cryptojacking” Case
Earlier today, in federal court in Brooklyn, Charles O. Parks III, also known as “CP3O,” pleaded guilty to wire fraud for operating a large-scale illegal “cryptojacking” operation.  As part of the sch...
052
Reposted by techy
Disney Prime Video + ᵖᵃʳᵒᵈʸ @disneyprimevideo.bsky.social · 06/12/2024
Rural Juror #2 (2024)
Justin Kemp (Nicolas Hoult) and Constance Justice (Jenna Maroney) are plural jurors who endure unsure furor in one of those courtroom movies where they figure it out at the last second through a series of audio flashbacks that they didnt need to do for you to get it.
16845116
Reposted by techy
Eslam Salem @netcodex.bsky.social · 06/12/2024
We are happy to introduce our latest tool "Supply Chain Firewall" 🎉 by @ikretz.bsky.social The tool detects & prevents installation of malicious packages in local development environment. Read more securitylabs.datadoghq.com/articles/int... And give it a try github.com/DataDog/supp...
securitylabs.datadoghq.com
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs
Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages
0117
Reposted by techy
Jonny Johnson @jonny-johnson.bsky.social · 04/12/2024
Microsoft's Threat-Intelligence ETW provider now supports events to identify token impersonation attacks. I wrote a blog on these events and how Microsoft is surfacing them: jsecurity101.medium.com/behind-the-m...
jsecurity101.medium.com
Behind the Mask: Unpacking Impersonation Events
Introduction
092
techy @techy.detectionengineering.net · 04/12/2024
Detection Engineering Weekly Issue 95 is LIVE! buff.ly/4gmqbvv In this post: * 💎 by Mark Ellzey on Censys' new automated hunting tool, Censeye. Tons of great infrastructure pivoting tips for folks getting into this space * Fabian Bader on EDR Silencer techniques using Windows' NRPT
buff.ly
Det. Eng. Weekly #95 - I prefer Vegas in December
there's something nice about 65 degree weather in the desert
1152
techy @techy.detectionengineering.net · 29/11/2024
Anyone going to reinvent next week?
110
Reposted by techy
Catalin Cimpanu @campuscodi.risky.biz · 28/11/2024
Censys has released Censeye, a tool to identify hosts with characteristics similar to a given target github.com/Censys-Resea...
github.com
GitHub - Censys-Research/censeye
Contribute to Censys-Research/censeye development by creating an account on GitHub.
0436
Reposted by techy
techy @techy.detectionengineering.net · 27/11/2024
Detection Engineering Weekly Issue 94 is live! www.detectionengineering.net/p/det-eng-we... In this post: * 💎 by Volexity's Sean Koessel Steven Adair and Tom Lancaster on the nearest neighbor attack they presented at CYBERWARCON. * Hal Pomeranz on Linux LKM persistence detection opportunties
detectionengineering.net
Det. Eng. Weekly #94 - I tune all the rules, yeah, somebody gotta do it
🗣️🗣️MUSTAAAAAAAAAAAAARD🗣️🗣️
1142
techy @techy.detectionengineering.net · 27/11/2024
Detection Engineering Weekly Issue 94 is live! www.detectionengineering.net/p/det-eng-we... In this post: * 💎 by Volexity's Sean Koessel Steven Adair and Tom Lancaster on the nearest neighbor attack they presented at CYBERWARCON. * Hal Pomeranz on Linux LKM persistence detection opportunties
detectionengineering.net
Det. Eng. Weekly #94 - I tune all the rules, yeah, somebody gotta do it
🗣️🗣️MUSTAAAAAAAAAAAAARD🗣️🗣️
1142
Reposted by techy
Hexacorn @hexacorn.bsky.social · 23/11/2024
How to debug Windows service processes in the most old-school possible way... www.hexacorn.com/blog/2024/11...
1174
techy @techy.detectionengineering.net · 25/11/2024
Cool to see more training around detection engineering outside of major firms like SANS!
1130
Reposted by techy
The Taggart Institute @taggartinstitute.org · 19/11/2024
New Course: Automated Detection with Sigma Two courses in one week?!? We're so excited to share with you a new course that Faculty member @hgb.crowstrike.zip has been working hard on for about a year now! taggartinstitute.org/p/detection-...
taggartinstitute.org
The Taggart Institute: Master Your Craft
The Taggart Institute exists to provide low-cost, high-quality technology training to everyone in a welcoming, supportive community.
1228
Reposted by techy
vx-underground (automated mirror) @vxundergroundre.bsky.social · 25/11/2024
Yesterday Banshee Stealer, the MacOS-based Malware-as-a-Service infostealer, had their source code leaked online. As a result of the leak they've shut down their operations. We've archived the leak and made it available for download on GitHub. github.com/vxundergroun...
github.com
GitHub - vxunderground/MalwareSourceCode: Collection of malware source code for a variety of platforms in an array of different programming languages.
Collection of malware source code for a variety of platforms in an array of different programming languages. - vxunderground/MalwareSourceCode
05718
techy @techy.detectionengineering.net · 25/11/2024
OK last starter pack, I promise :). I wanted to collect a list of all security newsletter and podcast creators and put it into one spot, so here you go! go.bsky.app/Hrn5N6u I'll be adding more as they join bluesky
172
techy @techy.detectionengineering.net · 24/11/2024
Just added a boatload of new detection engineers who joined Bluesky this week. Make sure to check this starter pack out
2134
Reposted by techy
David Oxley @oxley.io · 09/11/2024
I’ve created a Starter Pack around cyber threat intelligence to make it easier to find that community here on Bluesky. Let me know of folks I missed, as I’m sure there are many! go.bsky.app/TxQYHap
3218370
Reposted by techy
Mark Manning @antitree.com · 23/11/2024
An implementable security guardrail policy for cloud www.cloudguardrails.com#cloud-guardr...
cloudguardrails.com
Cloud Guardrails
An open-source collection of cloud infrastructure best practices, for bootstrapping or improving your own cloud platform.
0114
Reposted by techy
Sky Sentry @skysentry.bsky.social · 23/11/2024
This account will be only used to monitor and create lists so far right groups and others who are attempting to manipulate the platform and target every day users with hate, conspiracy, and misinformation are removed from your feeds.
3992637502
techy @techy.detectionengineering.net · 23/11/2024
Speaking of nostalgia. @dieworkwear.bsky.social is so good at bringing up stories of a past internet where forums dominated as the technology for subcultures. I miss the sheer ridiculousness, pettiness and playful nature of these places. You could tune in, shitpost and tune out without worry.
030
Reposted by techy
derek guy @dieworkwear.bsky.social · 23/11/2024
I was on a menswear forum with Michael Anton for many years. If you plan to work in the Trump White House and have a petty rivalry with him, let me know. I can help you say things around him that will get under his skin. @sebgorka.bsky.social
Screenshot of a tweet from John Hudson, who covers cover diplomacy and national security for The Washington Post. The tweet says: "New: Michael Anton was a leading candidate to become deputy national security adviser but pulled himself out of contention when he was told he would have to work with Sebastian Gorka at the NSC, per sources. 

Last year, Anton wrote about his strained relationship with Gorka, which in Anton’s account stemmed from Gorka irritating senior White House staff by exaggerating his own role in writing a speech Trump delivered in his first term. Anton said he was charged with clarifying to the media that Gorka did not draft the speech, an act that culminated in Gorka calling Anton a “coward” and scolding him in a Fox News green room, according to his account.

Anton did not immediately respond to a request for comment, while Gorka told The Post: “I don’t comment to the fake failing news."

Anton expected to be in contention for other administration jobs."
815986434
techy @techy.detectionengineering.net · 23/11/2024
Okay I’ve gotten the detection and CTI starter pack. What other big security starter packs are there?
420