analyst@soc-hub:~$ detection-intel --mode live
// Hunt Smarter.
Detect Faster.
Respond Better.
Practical detection guides, hunt playbooks, and tool reviews for SOC analysts and detection engineers. Real techniques, real rules, real tradecraft.
98 Articles
86 Detection Guides
9 Hunt Playbooks
33 MITRE Mapped
// Featured Intel
view all → Detection Guide T1210
Detecting CVE-2026-41089 Netlogon RCE Exploitation Attempts
Detection guidance for CVE-2026-41089, the pre-authentication Netlogon stack buffer overflow actively exploited against domain controllers. Covers network-layer Suricata rules, Windows event log indicators, and a full Sigma detection for anomalous NRPC traffic and post-exploitation behaviour.
Detection Guide T1003.001
Detecting LSASS Credential Dumping on Windows
A practical detection guide for identifying Mimikatz, procdump, and other tools targeting LSASS memory. Covers Sysmon events, Windows Security logs, and Sigma rules you can deploy today.
// Recent Entries
view all → 2026-08-24 Detection Guide Detecting Shai-Hulud's New Persistence Trick: Weaponized VS Code Tasks and Claude Code Settings → 2026-08-23 Detection Guide Detecting BYOEDR: When Attackers Install a Second EDR to Kill Your First One → 2026-08-22 Detection Guide Detecting RedC2 4.0: Trojanized npm Packages Dropping an AI-Assisted Linux Implant → 2026-08-21 Hunt Playbook Hunting Cloud Log Tampering: Detecting Disable or Modify Cloud Logs (T1562.008) → 2026-08-19 Detection Guide Detecting C2Looper: A Ransomware Backdoor That Turned GitHub Into Its Full C2 Backend → 2026-08-19 Detection Guide Detecting MacSync: macOS ClickFix Infostealer Abusing LaunchAgent Persistence →
// intel feed
Stay Current on Detection Engineering
Subscribe to the RSS feed for new detection guides, hunt playbooks, and tool reviews as they're published.