Sign in

techy

@techy.detectionengineering.net
1.6K followers 408 following 70 posts

Creator of Detection Engineering Weekly (detectionengineering.net), Sec Research/Intel/Detection @ Datadog

PostsRepliesMedia
techy @techy.detectionengineering.net · 24/09/2025
This post is sponsored by detections.ai! Tired of manually writing detection rules? detections.ai uses AI agents to convert threat intel into SIGMA, SPL, KQL, YARA rules automatically. Join 7,500+ detection engineers in the community. Use code "DEW" to get started: detections.ai
detections.ai
detections.ai
View and interact with detection rules shared by the community
000
techy @techy.detectionengineering.net · 24/09/2025
Threats: Microsoft seizes 338 RaccoonO365 sites, domains and panels, Two teenagers charged for London transport outage from August 2024, BlackLotus Labs latest research on SystemBC, Oliver Smith TTP updates for DPRK's BeaverTail malware family
100
techy @techy.detectionengineering.net · 24/09/2025
* Garv Kamra's first foray into writing SIEM detections * Jacob Zalesky first blog post ever (!) on threat hunting ideas in AWS
100
techy @techy.detectionengineering.net · 24/09/2025
* Ryan Tomcik on co-occurring detection ideation using composite rules in Google SecOps * Amitai Cohen's take on effective work & task prioritization with a gaming analogy near and dear to my heart (RTS games baby!) * Hanif Kurniawan A. helps readers detect log source outages in Wazuh
100
techy @techy.detectionengineering.net · 24/09/2025
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability In this post: * 💎 by Dirk-jan Mollema discloses a cross-tenant Azure vulnerability that gives access to any Azure tenant, with detection opportunities to boot! www.detectionengineering.net/p/dew-130-go...
detectionengineering.net
DEW #130 - God-mode Azure vulnerability, Composite Detections & Detection Observability
power overwhelming
120
techy @techy.detectionengineering.net · 22/06/2025
I'm starting a new series on Detection Engineering called the Detection Field Manual. I wanted to publish < 10 minute reads on threat detection topics I've built in the field, at conferences and our interviews for candidates at Datadog. Here's issue 1! www.detectionengineering.net/p/detection-...
detectionengineering.net
Detection Engineering Field Manual #1 - What is a Detection Engineer?
Why does Detection Engineering matter to a security org?
191
techy @techy.detectionengineering.net · 10/05/2025
I'm so excited to announce that Datadog Security Research is launching a FREE, fully-online, Detection Engineering focused conference called Datadog Detect! bit.ly/datadog-detect Our lineup is incredible with experts in the field of detection, response and threat intelligence.
bit.ly
Datadog Detect: Scale your Security Operations with Detection Engineering | Datadog
See metrics from all of your apps, tools & services in one place with Datadog's cloud monitoring as a service solution. Try it for free.
0103
techy @techy.detectionengineering.net · 27/04/2025
Found just outside Moscone North for RSA. Now I'm pumped for my talk tomorrow. #hacktheplanet
021
techy @techy.detectionengineering.net · 09/04/2025
Detection Engineering Weekly Issue 109 is live! www.detectionengineering.net/p/det-eng-we...
detectionengineering.net
Det. Eng. Weekly #109 - I’m making a Hinge for detection engineers
Your profile is a rule, an alert is a match, and a false positive is a shitty date
042
techy @techy.detectionengineering.net · 02/04/2025
Detection Engineering Weekly issue 108 is live! www.detectionengineering.net/p/det-eng-we...
detectionengineering.net
Det. Eng. Weekly #108 - Can any1 in the IC add me to their Signal group?
Just tryna forward some reels and feelin left out rn
040
techy @techy.detectionengineering.net · 09/02/2025
@sekoia.io FYI your TLS cert is showing invalid due to date expiration for *.sekoia.io
120
techy @techy.detectionengineering.net · 04/02/2025
I love it when you guys go deep into a topic. The deepseek episode was a great example.
032
techy @techy.detectionengineering.net · 04/02/2025
Weekly: 1 hour Deep dives: 2-3 hours
120
techy @techy.detectionengineering.net · 22/01/2025
Browns coming in last yet again
030
Reposted by techy
SentinelOne @sentinelone.com · 20/01/2025
🍎👿 The key macOS malware families of 2024: This past year saw a sharp rise in sophisticated campaigns targeting macOS users in the enterprise and the increasing adoption of cross-platform development frameworks.
s1.ai
2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise
Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.
1114
Reposted by techy
Tom Hegel @hegel.bsky.social · 09/01/2025
I’m biased, but wow—it’s so refreshing to get updates that genuinely help me better track threat actors. 🔥 www.validin.com/blog/threat_...
validin.com
Tracking Threat Actors with Validin | Validin
Quickly identify threat actors and discover malicious infrastructure using Validin by viewing detailed descriptions on thousands of threat actors that Validin has cataloged
0113
techy @techy.detectionengineering.net · 09/01/2025
Bout to go wheels up!
130
Reposted by techy
6mile @6mile.githax.com · 08/01/2025
Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?
2408
techy @techy.detectionengineering.net · 08/01/2025
There has been for years! Just starting to see it be more impactful
040
Reposted by techy
Whitney Champion 🍪 @whit.zip · 07/01/2025
🎉 link and docs and details: nims-template.notion.site
nims-template.notion.site
Notion Incident Management System (NIMS) | Notion
Use the Template
051
Reposted by techy
Eric Capuano @eric.zip · 07/01/2025
🚀 Excited to announce the alpha release of NIMS - a Notion-based Incident Management System! Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features. #InfoSec #DFIR #IncidentResponse #SecOps #Notion
Logo for Notion Incident Management System (NIMS)
47321
Reposted by techy
lazarusholic @lazarusholic.bsky.social · 06/01/2025
"North Korea-nexus Golang Backdoor/Stealer from Contagious Interview campaign" published by dmpdump. #ContagiousInterview, #DPRK, #CTI dmpdump.github.io/posts/NorthKorea_…
012
techy @techy.detectionengineering.net · 31/12/2024
Hi wanna “make plans”?
000
Reposted by techy
da share z0ne @dasharez0ne.bsky.social · 18/12/2024
IF IT AINT EXECUTTABLE IT AINT FOR ME - dashare.zone ADMIN
A SKLEATON WHO DOSENT HAVE THAT MUCH SPARE TIME FLICKEN OFF THERE COMPUTER YET AGAIN, BECUASE THE SOLUTION TO THERE PROBLEM IS TO DOCKER SOME KIND OF SHIT FROM OPEN SOURCE OR WHAT EVER, BIG NO THANK'S TO THAT , AND DA TEXT SAYS "THE ONLY DOCKER MY ASS IS EVER GONGA INSTALL IS STAIN RESISTENE BROWN WORK PANTS" - DASHARE.ZONE ADMIN - I WILL NEVER USE "GO" I WILL NEVER APT-GET DA ONLY PACKAGE IM INTRESTED IN HAS A BOW ON TOP AND IT S FROM SANTA MOTHER FUCKER - DASHARE.ZONE ADMIN
034444
techy @techy.detectionengineering.net · 29/12/2024
Read the book twice and watched the series several times. Captain Winters is one of the top 3 leaders I try to emulate
020
techy @techy.detectionengineering.net · 29/12/2024
We still have a “purity” problem in infosec. People want super technical resources but don’t want them to advertise anything to survive or grow their brand. They want a mold that looks like DEFCON 2005 and hate anything that looks different. Doesn’t seem very hacker to me 🤷
130
techy @techy.detectionengineering.net · 29/12/2024
Even with the OPs main text, those are all great resources. There’s some actual charlatans like jonathandata1, but 95% of the people posted come from posters who seem just upset that they are not technical enough to their standards
120
techy @techy.detectionengineering.net · 29/12/2024
The cybersecurity subreddit has a thread on influencers and “who to avoid because of xyz”. These threads irk me because there’s no clear measurement and lots of gate keeping around who is allowed to post stuff and who isn’t. www.reddit.com/r/cybersecur...
reddit.com
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
240
techy @techy.detectionengineering.net · 26/12/2024
I’ve been pretty sick for the last 2 weeks, but Christmas holiday has been a much needed break for rest and recovery. Take care of yourselves people; I think stress contributed a ton to this, and being mindful and in the present has helped me out a lot. And lots of Christmas food.
270
techy @techy.detectionengineering.net · 22/12/2024
telling chatgpt my editor in a very blunt and snarky way, as all vim users do
010
Reposted by techy
Filippo Valsorda @filippo.abyssdomain.expert · 22/12/2024
The TLS Protocol Version 1.0 RFC, January 1999, in ugly meme form.

Top text:
I am not a toy
I am not a Christmas present
I am a 30+ years commitment

Bottom text:
Please think hard before you give someone
an Internet standard this Christmas
61100213
techy @techy.detectionengineering.net · 17/12/2024
Today is not a good day. Our dog needed a vet visit because he was weak and not eating. Turns out he had blood and fluid throughout his abdomen due to cancer. He was an amazing friend and family member, and tomorrow’s issue will be somber but commemorative with lots of pupper pics. Hug your dogs!
6210
Reposted by techy
Chris Farris @jcfarris.bsky.social · 17/12/2024
You've got to be a total wanker to name a law after yourself, and guess what! www.chrisfarris.com/post/three-l...
chrisfarris.com
Farris's Three Laws of Auto Remediation - Chris Farris
In this post, I present three laws of Cloud Security Robotics with homage to a SciFi great.
001
Reposted by techy
derek guy @dieworkwear.bsky.social · 15/12/2024
love these looks from Proper Cloth's new lookbook titled "New Ivy." even the grey shetland knit with black jeans and small dress watch looks great.
A man wears a taupe glen check Shetland tweed sport coat with a light blue dress shirt and mid-gray worsted trousers. he has a black belt, black loafers, and black watch strap carrying a silver dress watch. He also has a bit of silver jewelry in the form of necklaces and rings.A man wears a olive herringbone tweed sport coat with white jeans and a dark green button-up shirt. He's also wearing a bit of gold jewelry in the form of rings and bracelets, as well as a black watch strap carrying a dress watchA man wears a brown tweed sport coat with flapped patch pockets. It's paired with an ecru button-up shirt, tan chinos, brown belt, white ribbed tank, and silver necklacesA man wears a gray Shetland sweater with black jeans. He also has some rings, bracelets, and a small silver dress watch on a black leather watch strap.
1125430235
Reposted by techy
Catalin Cimpanu @campuscodi.risky.biz · 10/12/2024
DeFi platform Radiant Capital says North Korean hackers were behind the theft of over $50 million worth of assets from its servers in October this year. Radiant says it was hacked after an employee opened a malicious file received from a former contractor via Telegram: medium.com/@RadiantCapi...
medium.com
Radiant Capital Incident Update
2024–12–06
0104
Reposted by techy
netbiosX @netbiosx.bsky.social · 08/12/2024
github.com
GitHub - JoelGMSec/Invoke-Stealth: Simple & Powerful PowerShell Script Obfuscator
Simple & Powerful PowerShell Script Obfuscator. Contribute to JoelGMSec/Invoke-Stealth development by creating an account on GitHub.
172
Reposted by techy
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 06/12/2024
zizmor would have caught the Ultralytics workflow vulnerability blog.yossarian.net/2024/12/06/zizmo… #security #oss
2177
Reposted by techy
Ryan Naraine @ryanaraine.bsky.social · 07/12/2024
NEW pod alert! Turla caught stealing from a Pakistani APT, fourth-party espionage, threat actor attribution. Plus, a Monokle-like spyware finding, Salt Typhoon disinfections and Romania's election crisis over Russian interference via TikTok. @craiu.bsky.social @jags.bsky.social
185
Reposted by techy
Security Cryptography Whatever @scwpod.bsky.social · 07/12/2024
NEW EPISODE! Our esteemed guests @justinschuh.com and @matthewdgreen.bsky.social joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or 'just' a major fuckup: securitycryptographywhatever.com/2024/12/07/d... www.youtube.com/watch?v=i0eo...
youtube.com
Dual_EC_DRBG with Justin Schuh and Matthew Green
YouTube video by Security Cryptography Whatever
62714
techy @techy.detectionengineering.net · 07/12/2024
There's an excellent writeup on the attack chain via the vulnerability here bsky.app/profile/yoss... . Thank you @yossarian.net!
020
techy @techy.detectionengineering.net · 07/12/2024
If indeed the problem is pushing malicious code and publishing directly to PyPi itself, there's only one listed account owner (though there could be more): Glenn Jocher. Email listed directly on PyPi. If someone got access to this email, you could search for it inside infostealer or breach databases
110
techy @techy.detectionengineering.net · 07/12/2024
Quick guarddog scan found the offending code on one of the malicious versions. Unremarkably, its dropping cryptomining binaries for Linux and MacOS. An OSV entry for ultralytics malware still hasn't made it to the main osv database
110
techy @techy.detectionengineering.net · 07/12/2024
Ultralytics, a python package with close to 6.4 million downloads per month, was backdoored to run a cryptominer. Running theory from the reported GitHub issue is a GitHub action injection attack, but theres also evidence that the malicious code was published directly via PyPi and skipped CI/CD
1104
techy @techy.detectionengineering.net · 07/12/2024
🥺 added!
110
techy @techy.detectionengineering.net · 07/12/2024
First time I’ve seen a successful arrest and plea of a large crypto jacking campaign. Nebraska man leveraged stolen cloud resources to mine crypto for 3.5 million www.justice.gov/usao-edny/pr...
justice.gov
Nebraska Man Pleads Guilty in Multi-Million Dollar “Cryptojacking” Case
Earlier today, in federal court in Brooklyn, Charles O. Parks III, also known as “CP3O,” pleaded guilty to wire fraud for operating a large-scale illegal “cryptojacking” operation.  As part of the sch...
052
Reposted by techy
Disney Prime Video + ᵖᵃʳᵒᵈʸ @disneyprimevideo.bsky.social · 06/12/2024
Rural Juror #2 (2024)
Justin Kemp (Nicolas Hoult) and Constance Justice (Jenna Maroney) are plural jurors who endure unsure furor in one of those courtroom movies where they figure it out at the last second through a series of audio flashbacks that they didnt need to do for you to get it.
16845116
Reposted by techy
Eslam Salem @netcodex.bsky.social · 06/12/2024
We are happy to introduce our latest tool "Supply Chain Firewall" 🎉 by @ikretz.bsky.social The tool detects & prevents installation of malicious packages in local development environment. Read more securitylabs.datadoghq.com/articles/int... And give it a try github.com/DataDog/supp...
securitylabs.datadoghq.com
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs
Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages
0117
techy @techy.detectionengineering.net · 06/12/2024
👋 would love an add as a content creator!
010
Reposted by techy
Jonny Johnson @jonny-johnson.bsky.social · 04/12/2024
Microsoft's Threat-Intelligence ETW provider now supports events to identify token impersonation attacks. I wrote a blog on these events and how Microsoft is surfacing them: jsecurity101.medium.com/behind-the-m...
jsecurity101.medium.com
Behind the Mask: Unpacking Impersonation Events
Introduction
092