analyst@soc-hub:~$ detection-intel --mode live
// Hunt Smarter.
Detect Faster.
Respond Better.
Practical detection guides, hunt playbooks, and tool reviews for SOC analysts and detection engineers. Real techniques, real rules, real tradecraft.
101 Articles
89 Detection Guides
9 Hunt Playbooks
36 MITRE Mapped
// Featured Intel
view all → Detection Guide T1210
Detecting CVE-2026-41089 Netlogon RCE Exploitation Attempts
Detection guidance for CVE-2026-41089, the pre-authentication Netlogon stack buffer overflow actively exploited against domain controllers. Covers network-layer Suricata rules, Windows event log indicators, and a full Sigma detection for anomalous NRPC traffic and post-exploitation behaviour.
Detection Guide T1003.001
Detecting LSASS Credential Dumping on Windows
A practical detection guide for identifying Mimikatz, procdump, and other tools targeting LSASS memory. Covers Sysmon events, Windows Security logs, and Sigma rules you can deploy today.
// Recent Entries
view all → 2026-08-26 Detection Guide Detecting EDR-Freeze: The WerFaultSecure Race Condition That Puts Security Agents Into a Coma → 2026-08-26 Detection Guide Detecting ICMP-Ghost: A Fileless Ptrace-Injected C2 Agent Tunnelling Over ICMP and DNS → 2026-08-25 Detection Guide Detecting CVE-2026-55040: SharePoint JWT Authentication Bypass Exploitation → 2026-08-24 Detection Guide Detecting Shai-Hulud's New Persistence Trick: Weaponized VS Code Tasks and Claude Code Settings → 2026-08-23 Detection Guide Detecting BYOEDR: When Attackers Install a Second EDR to Kill Your First One → 2026-08-22 Detection Guide Detecting RedC2 4.0: Trojanized npm Packages Dropping an AI-Assisted Linux Implant →
// intel feed
Stay Current on Detection Engineering
Subscribe to the RSS feed for new detection guides, hunt playbooks, and tool reviews as they're published.