Excited to share my new project: AttackRuleMap
This project maps #AtomicRedTeam simulations to open-source detection rules like #SigmaRules and #Splunk ESCU rules (maybe more in the future).
Currently for Windows, with plans to support more platforms.
https://t.co/O52271h4BW
Now, I’ve expanded it with two major new layers on #n8n:
🔴 Attack Testing via #AtomicRedTeam#MCP automatically simulates #MITRE techniques.
🟢 Detection Testing via #Splunk MCP verifies detections by running SPL tests and adjusting queries dynamically.
https://t.co/dlIBiLPRSf
🚀 I’ve been working on something I’m really excited about lately.
It started as an experiment in #AIAgent automation in #n8n, but it turned into a pretty capable system that now handles most of the #detectionengineering flow on its own.
https://t.co/ApcsD08ZaU
I’m honored to have had the opportunity to share my insights in the 2025 State of Detection Engineering Report by Anvilogic & SANS Institute.
Thank you to the team that organized this awesome report!
You can explore the full report here: https://t.co/BbaXeb0Lff
New Sigma release r2025–02–03 is available for download.
🌟5 New Rules
🛡️5 Rule updates
🔬14 Rule Fixes
Explore the full release -> https://t.co/cZbbtbwGQp
This release saw the first wave of contribution from the @TheDFIRReport in a new collab we started with the team. 🔥
Without forgetting, a special thanks to the many contributors that helped shape this release, specifically
Daniel Koifman, @DefensiveDepth, Djordje Lukic, @frack113, GtUGtHGtNDtEUaE, Josh Nickels, @krdmnbrk, @cyb3rops, samuelmonsempessenthorus, Renan LAVAREC, @Kostastsale@X__Junior
The current version of the https://t.co/qPi4gXSUZ7 project has Sigma and Splunk rules. I wonder if it could support more platforms by adding a drop down button with the platform list and redirecting to https://t.co/IYl5plGwrW. Sounds possible :)
#DetectionEngineering#BlueTeam
@infosecb Thanks for sharing, it's awesome. Soft skills are the hidden treasures for a DE, especially product manager/owner skills. As a suggestion, scrum/kanban or agile might be added.
I recently stumbled upon https://t.co/46XST6Uwx6 - it's a great resource for self-learners that appreciate some structure.
For anyone who might find it useful, I threw together a basic "Threat Detection Engineer" roadmap:
https://t.co/2Ms1r9asCO
https://t.co/qPi4gXSUZ7 now supports Linux attack and detection rules, in addition to Windows!
With 88 new Linux attacks added, this open-source solution, aligned with Sigma and Splunk rules, takes multi-platform threat detection to the next level.
🚀 What’s new on https://t.co/qPi4gXSn9z?
💻 New Column: Platform currently shows only Windows, but Linux support 🐧 is coming soon!
🔗 JSON Export to integrate anything.
🗓 Last Updated Date of the contents
☀️ Switch to Light Mode
https://t.co/PoQ2WToMFO
#blueteam#cyber
Check out the latest addition to awesome-detection-engineering: AttackRuleMap
AttackRuleMap is a clean and easy to use table of MITRE ATT&CK techniques and any associated Sigma or Splunk rules.
Thanks @krdmnbrk for the add!
https://t.co/YlFFEDw8Dw
Excited to share my new project: AttackRuleMap
This project maps #AtomicRedTeam simulations to open-source detection rules like #SigmaRules and #Splunk ESCU rules (maybe more in the future).
Currently for Windows, with plans to support more platforms.
https://t.co/O52271h4BW
What’s new on https://t.co/w5pimqLYqo?
🧪 Explore a collection of sample attack tests, different levels.
📂 Upload YAML files, whether it’s a single test or a whole MITRE technique file.
☀️ "Dark Mode? Not my style." Good news: Light Mode is now available!
#AtomicRedTeam