Got a great security blog post to share? Submit it here for potential inclusion in my weekly roundups.
I feature posts that help detection engineers, threat hunters, and defenders build better detections and understand adversary behavior:
- Detection logic and analytics - Novel detection approaches, specific techniques, behavioral analytics, correlation rules
- Adversary techniques deep-dives - Malware analysis, rootkit breakdowns, offensive tool research that informs defensive detection
- Detection engineering tradecraft - Testing detections, reducing false positives, detection-as-code, pipeline architecture
- Telemetry and visibility - Log sources, EDR internals, instrumentation gaps, collection strategies
- Threat research with detection applicability - Attack primitives, evasion techniques, and how to detect them
- Tooling and automation - Detection development tools, SIEM/detection platform deep-dives, automation workflows
- Marketing and vendor posts are fine - only when they contain practical knowledge dissemination, are NOT gatekept by sign up forms, and aren't plastering readers with low-effort marketing and product slop
What I look for: Technical depth, practical applicability for detection engineers, attention to detail, and clear explanations that help defenders build better detections.
~~ IF YOU ARE NEW IN THE FIELD, OR IF IT'S YOUR FIRST BLOG/SET OF BLOGS EVER, PLEASE SUBMIT! :D ~~
What I look for: Technical depth, practical applicability for detection engineers, attention to detail, and clear explanations that help defenders build better detections.
- I review all submissions but feature only ~5-10 posts per week
- Not every submission will be selected
- Featured posts may appear weeks after submission depending on the week's theme