#Detectionascode

DEF CON Group 420dcg420
2025-12-31

‼️We are introducing a tool for the first time…

🔨Hefaistos - AI assisted Detection-as-Code platform

📅 We are starting on January 31, 2025

Details and waiting list here - blog.dcg420.org/from-static-te

Tedi Heriyantotedi@infosec.exchange
2025-09-22
Tedi Heriyantotedi@infosec.exchange
2024-08-03
Tedi Heriyantotedi@infosec.exchange
2024-05-30

SIEM 4.0: The Essentialist Evolution: jacknaglieri.substack.com/p/ge

What to expect in SIEM 4.0:

- Prioritizing impactful MITRE tactics rather than complete ATT&CK coverage.

- Shifting from atomics to risk-based alerts that analyze groups of actions.

- Opening up the data lake and introducing new criteria for open data platforms.

- Controlling low-quality alerts through the adoption of “as code” principles.

- Using AI to automate routine tasks allows humans to focus on high-value work.

#siem #mitreattack #riskbased #DetectionAsCode

Tedi Heriyantotedi@infosec.exchange
2024-02-23

Getting Started with Detection-as-Code and Chronicle Security Operations from David French:

- In Part 1 David shares the principles and benefits of managing detection rules as code, an example detection engineering workflow used by security teams, and how to configure a CI/CD pipeline job in GitLab to pull existing detection rules via Chronicle’s API and commit them to a GitLab project: googlecloudcommunity.com/gc/Co

- In Part 2, he demonstrates how to create and modify detection rules via Chronicle’s API: googlecloudcommunity.com/gc/Co

#DetectionAsCode #detectionengineering #chroniclesecurityoperations

Claus Cramon Houmannclaushoumann
2024-02-22

In about 2 weeks we’re releasing something you might wanna see if you like or or or -> TIDeMEC which implements will be released at the FIRST Symphony Amsterdam

signalblur 📡🛸signalblur
2022-04-27

Ever wonder how works, with a real sample process we had implemented - then check out an old I wrote on the topic:

signalblur.io/detectors-as-cod

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst