Q3 detection rule pack — persistence and execution
Eleven Sigma rules and three YARA signatures covering the persistence and execution techniques that showed up most in this quarter's casework, with measured false-positive budgets.
Incident teardowns, detection engineering and adversary emulation, written the way they get written in a notebook: the artifact, the query that found it, the thing that turned out to be wrong, and the rule that came out the other end.
Eleven Sigma rules and three YARA signatures covering the persistence and execution techniques that showed up most in this quarter's casework, with measured false-positive budgets.
A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.
Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.
Entropy, subdomain cardinality and query-rate shape — three statistics that find a covert channel faster than any rule matching a known tool.
Six months of a detection lab that was impressive to look at and useless to work in, and the four changes that fixed it.
Security Artifacts is free to read. A membership adds the parts that take the longest to produce — full incident write-ups with the evidence attached, the rule packs, and the wire as a machine-readable export.