Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

the-d3fender

stats-default

Detection Engineering | Telemetry Architecture & Detection-as-Code | Application Security | DevSecOps

I design, validate, and automate high-fidelity detection logic and telemetry pipelines. My work focuses on bridging threat intelligence with software engineering principles, transforming adversary TTP research into tested, continuous Detection-as-Code (DaC) infrastructure.


Core Technical Focus

Category Primary Focus & Tooling
Detection Logic Sigma, YARA, KQL, SPL, Falco, Suricata
Telemetry & Logging OS-level Telemetry (ETW, Sysmon, eBPF, Auditd), Log Pipelines
Automation & CI/CD Detection Rule Linting, Unit Testing (Pytest), GitHub Actions
Validation & Hunting Threat Emulation (Atomic Red Team), MITRE ATT&CK Mapping
Security Testing Penetration Testing, Red Teaming, Purple Teaming

Engineering Principles

  1. High-Signal Quality: Detection logic must provide actionable context and prioritize low false-positive rates over alert volume.
  2. Detection-as-Code: Rules are version-controlled, peer-reviewed, tested against telemetry datasets, and deployed via CI/CD.
  3. Telemetry-Driven: Effective coverage begins by engineering the underlying event streams before writing detection logic.

Verification & Contact

  • Professional Identity: the-d3fender/ across technical platforms
  • Publications & Research: Research Files

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors