Skip to content

Latest commit

Β 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 

Repository files navigation

##.o0Γ—XΓ—0o.| DΝ“Μ½eΝ“Μ½aΝ“Μ½tΝ“Μ½hΝ“Μ½ RΝ“Μ½eΝ“Μ½sΝ“Μ½oΝ“Μ½uΝ“Μ½rΝ“Μ½cΝ“Μ½eΝ“Μ½sΝ“Μ½ |.o0Γ—XΓ—0o.##:

πŸ‘ΎπŸ’»Description

In this repo, lets just say it can store everything what you are looking for. Maybe its relating to Cyber Operations including Detection Eng., Threat Hunting, Threat Intel, or Phishing. This Cyber space is broad, it includes various niches, often times they operate separately where they work individually, there are most times these teams work together. Its important that we incorporate for these teams to unify and be mindful that reframe from being siloed. There is a lot of overlapping in these niches. In order to explain some of the nuances and similarities between each niches. Personally, my learning style is visualizations and real-world analogies. Learning should be fun right? I don't know about you but I learn best from understanding and memorizing that relates to what I can relate to.

πŸ“š Books

πŸ“„ Blogs

πŸ“Ί YouTube Playlist


🧠 Core Competency Stack

Domain Core Skills
🎯 Detection Engineering Detection logic, tuning, validation, Detection-as-Code
πŸ•΅οΈ Threat Hunting Hypothesis-driven hunting, behavioral analysis
🧠 Threat Intelligence IOC/TTP analysis, adversary research
πŸ”¬ Digital Forensics Windows artifacts, DFIR, investigation
πŸͺŸ Windows Security Internals, processes, persistence, execution
πŸ”Ž Query Engineering KQL, Splunk, Regex
βš™οΈ Automation PowerShell, scripting, CI/CD
πŸ“Š Telemetry Logs, events, endpoint/network data
🧩 Frameworks MITRE ATT&CK, Diamond Model, Pyramid of Pain
πŸ›‘οΈ Security Operations Detection, investigation, response

🧭 Suggested Learning Path

1. Build the Fundamentals β†’ TryHackMe Detection Engineering β†’ MITRE ATT&CK β†’ Pyramid of Pain β†’ Diamond Model

2. Start Building Detections β†’ Antisyphon SOC Detection Engineering β†’ TCM Security Detection Engineering for Beginners

3. Build Supporting Skills β†’ PowerShell β†’ Regex β†’ Splunk β†’ KQL

4. Understand the Operating System β†’ 13Cubed Digital Forensics β†’ SANS Forensics

5. Develop Hunting & Intelligence Skills β†’ Intel 471 β†’ Huntress research

6. Advance Your Detection Engineering β†’ SpecterOps Funnel of Fidelity β†’ Level Effect β€” Death of Windows

🎯 Goal: Move beyond simply writing detection rules. Develop the ability to understand operating systems, execute and observe attacks, identify useful telemetry, investigate adversary behavior, and translate that knowledge into high-fidelity detections.

Build the technical depth to understand what happened, the analytical skill to determine why it matters, and the engineering discipline to turn that knowledge into high-fidelity detections.

πŸ›‘οΈ Detection Engineering β€” Hands-On Learning & Guidepoints

A curated collection of hands-on labs, courses, videos, and readings for developing practical Detection Engineering, Threat Hunting, Digital Forensics, and Security Operations skills.


🧭 Detection Engineering Learning Path

A practical progression from fundamentals to advanced Detection Engineering:

                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚     FUNDAMENTALS      β”‚
                    β”‚                       β”‚
                    β”‚ MITRE ATT&CK          β”‚
                    β”‚ Pyramid of Pain       β”‚
                    β”‚ Diamond Model         β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚  DETECTION DEVELOPMENTβ”‚
                    β”‚                       β”‚
                    β”‚ Detection Engineering β”‚
                    β”‚ Detection-as-Code     β”‚
                    β”‚ Detection Logic       β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚   QUERY & AUTOMATION  β”‚
                    β”‚                       β”‚
                    β”‚ KQL                   β”‚
                    β”‚ Splunk                β”‚
                    β”‚ Regex                 β”‚
                    β”‚ PowerShell            β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚ OS & TELEMETRY        β”‚
                    β”‚                       β”‚
                    β”‚ Windows Internals     β”‚
                    β”‚ Digital Forensics     β”‚
                    β”‚ Security Artifacts    β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚ THREAT HUNTING        β”‚
                    β”‚                       β”‚
                    β”‚ Hypothesis Developmentβ”‚
                    β”‚ Adversary Behavior    β”‚
                    β”‚ Threat Intelligence   β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚ ADVANCED DETECTION    β”‚
                    β”‚                       β”‚
                    β”‚ Detection Fidelity    β”‚
                    β”‚ Detection-as-Code     β”‚
                    β”‚ CI/CD                 β”‚
                    β”‚ Continuous Tuning     β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

🎯 End Goal

Don't just learn how to write detection rules. Learn how to understand the adversary, the operating system, the telemetry, and the investigation process that makes a detection valuable.

The objective is to develop the ability to:

Understand the Attack

β†’ Execute / Emulate the Technique

β†’ Observe the Telemetry

β†’ Identify Relevant Artifacts

β†’ Develop a Detection

β†’ Validate the Detection

β†’ Tune for Fidelity

β†’ Operationalize

β†’ Hunt for Related Activity

β†’ Generate Intelligence

β†’ Improve the Detection

This creates a continuous feedback loop between Threat Intelligence β†’ Threat Hunting β†’ Detection Engineering β†’ Incident Response β†’ Intelligence.

                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚  THREAT INTELLIGENCE β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚
                            β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚   THREAT HUNTING    β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚
                            β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚ DETECTION ENGINEERINGβ”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚
                            β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚ INCIDENT RESPONSE   β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚
                            β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚   NEW INTELLIGENCE  β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚
                            └──────────────► ♻️ Recycle Phase/Loop ♻️

Core Philosophy:

Intelligence drives hypotheses. Hypotheses drive hunts. Hunts generate telemetry. Telemetry drives detections. Detections generate investigations. Investigations produce intelligence.

πŸš€ Detection Engineering β€” Hands-On Labs & Courses

Resource Focus Level
Antisyphon Training β€” SOC Detection Engineering Crash Course SOC detection engineering, lab simulation, VM-based exercises 🟒 Easy β†’ 🟑 Moderate
TryHackMe β€” Detection Engineering Detection engineering fundamentals, MITRE ATT&CK, Pyramid of Pain, Diamond Model 🟒 Beginner
TCM Security β€” Detection Engineering for Beginners Build a detection lab, execute attacks, and develop detections from observed activity 🟑 Moderate
Level Effect β€” Course Options Advanced Windows security, detection, and threat hunting concepts 🟒 Easy β†’ 🟑 Moderate

🧰 Supporting Technical Skills

⚑ PowerShell

PowerShell Quick Course β€” YouTube

Build foundational PowerShell skills for Windows administration, investigation, automation, and detection development.

πŸ”Ž Regular Expressions & Splunk

Lame Creations β€” Regex & Splunk Guides

Useful material for developing regex skills and working with Splunk searches and detection logic.

πŸ–₯️ KQL / Microsoft Security

KC7 Cyber β€” KQL Training

Hands-on training for learning Kusto Query Language (KQL) and applying query skills to security investigations and threat hunting.


πŸ”¬ Digital Forensics & Operating System Knowledge

13Cubed β€” Digital Forensics

Excellent resource for understanding Windows internals, digital forensics, artifacts, and investigative techniques.

Understanding how an operating system worksβ€”and what traces activity leaves behindβ€”is critical for developing effective detections.


πŸ•΅οΈ Threat Hunting & Threat Intelligence

πŸŽ₯ SANS Forensics

SANS Forensics β€” YouTube

Additional lectures, presentations, and technical content covering digital forensics, incident response, and investigative methodologies.


πŸ‡ Huntress Blog

Huntress β€” Security Research & Threat Intelligence

Ongoing research and write-ups covering threat actors, malware, incidents, adversary techniques, and practical security operations.

image β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €β €

Releases

Packages

Contributors