-
What a Good ICS Detection Looks Like in Practice
There is a lot of advice about ICS detection that talks about MODBUS, DNP3, and the protocol layers. This is the part that comes after the protocol talk: what a good detection actually looks like in the SIEM, and what the SOC analyst does with it
-
How to Build an Insider-Risk Programme That Actually Catches the Bad Cases
Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter
-
The Detection Rule That Changed How I Think About Fidelity
There is one detection rule in my career that genuinely changed how I think about detection fidelity. It was not a clever rule. It was a simple rule. The simplicity is what taught me the most. Here is the rule and what it taught me
-
How to Hire a Detection Engineer When You Have Never Hired One Before
Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire
-
The Six-Month Build: What a Real Detection Engineering Programme Looks Like
Most 'detection engineering programmes' are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs
-
What a Good Detection Engineer Actually Does All Day
The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right
-
Building a Detection Baseline: The Work Nobody Wants to Do
Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work
-
Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts
Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not
-
Living Off the Land: Why the Best Attackers Don't Look Like Attackers
Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…
-
The Insider Threat Problem Is Not What You Think
Your insider threat programme is aimed at the wrong target