analyst@soc-hub:~$ detection-intel --mode live
// Hunt Smarter.
Detect Faster.
Respond Better.
Practical detection guides, hunt playbooks, and tool reviews for SOC analysts and detection engineers. Real techniques, real rules, real tradecraft.
66 Articles
58 Detection Guides
6 Hunt Playbooks
25 MITRE Mapped
// Featured Intel
view all → Detection Guide T1210
Detecting CVE-2026-41089 Netlogon RCE Exploitation Attempts
Detection guidance for CVE-2026-41089, the pre-authentication Netlogon stack buffer overflow actively exploited against domain controllers. Covers network-layer Suricata rules, Windows event log indicators, and a full Sigma detection for anomalous NRPC traffic and post-exploitation behaviour.
Detection Guide T1003.001
Detecting LSASS Credential Dumping on Windows
A practical detection guide for identifying Mimikatz, procdump, and other tools targeting LSASS memory. Covers Sysmon events, Windows Security logs, and Sigma rules you can deploy today.
// Recent Entries
view all → 2026-07-20 Detection Guide Detecting Entra ID Cross-Tenant Synchronization Abuse → 2026-07-19 Detection Guide Detecting SNMP Router Configuration Theft: Sigma and KQL for CISA AA26-194A → 2026-07-18 Hunt Playbook Hunting Okta Compromise: Threat Hunting in Identity Provider Syslogs → 2026-07-17 Detection Guide Detecting Active Directory Password Spray Attacks (T1110.003): Sigma and KQL Detection Guide → 2026-07-16 Detection Guide Detecting AI-Assisted IAM Parallelism: CloudTrail Sigma Rules for Concurrent Credential Abuse → 2026-07-15 Detection Guide Detecting Kerberos Delegation Abuse: Unconstrained, Constrained, and RBCD Attack Paths (T1558) →
// intel feed
Stay Current on Detection Engineering
Subscribe to the RSS feed for new detection guides, hunt playbooks, and tool reviews as they're published.