1. How to Build an Insider-Risk Programme That Actually Catches the Bad Cases

    Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter

    Insider Threat Detection Engineering

  2. How to Hire a Detection Engineer When You Have Never Hired One Before

    Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire

    Detection Engineering

  3. Tabletop Exercises That Actually Prepare You for an Incident

    Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says 'we are well prepared.' Here is how to run one that is not theatre

    Purple Teaming

  4. The Six-Month Build: What a Real Detection Engineering Programme Looks Like

    Most 'detection engineering programmes' are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs

    Detection Engineering

  5. What a Good Detection Engineer Actually Does All Day

    The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right

    Detection Engineering

  6. Building a Detection Baseline: The Work Nobody Wants to Do

    Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work

    Detection Engineering

  7. How to Write a Purple Team Report That Actually Gets Read

    You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…

    Purple Teaming Red Team

  8. Living Off the Land: Why the Best Attackers Don't Look Like Attackers

    Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…

    Detection Engineering Red Team