InDetect FYIbyAlex Teixeira·Jun 23Testing AI Threat Hunting against Real-World KQL: A Side-by-Side TestA real-world experiment revealing where AI excels and where it still struggles. Here’s an honest breakdown of the gap.A response icon1A response icon1
InDetect FYIbyAlex Teixeira·Feb 23Whose endpoint is this… kali?!The thought process to uncover post-exploitation activity and rogue devices in enterprise networks
InDetect FYIbyAlex Teixeira·Jan 29Data Prevalence: The Game Changer in Threat Detection & IRBuilding compound, high-fidelity detection available for allA response icon3A response icon3
InDetect FYIbyAlex Teixeira·Jan 20Introducing > PowerShell.ExposedCommunity-driven pattern-based detection indicatorsA response icon2A response icon2
InDetect FYIbyAlex Teixeira·Dec 10, 2025Rethinking Benign Alerts: A New Perspective for Detection EngineeringBreaking down the false TP/FP dichotomy in the SOCA response icon1A response icon1
InDetect FYIbyAlex Teixeira·Nov 17, 2025Introducing the DRAPE Index: How to measure (in)success in a Threat Detection practice?Going Beyond the Cosmetics to Assess Detection QualityA response icon4A response icon4
InDetect FYIbyAlex Teixeira·Aug 25, 2025Malicious Encoded PowerShell: Detecting, Decoding & ModelingThe challenges and insights from dealing with this PS one-liner
InDetect FYIbyAlex Teixeira·May 1, 2025The Detection Opportunity CostWhat should drive picking one detection idea over another?A response icon3A response icon3
InDetect FYIbyAlex Teixeira·Mar 26, 2025Becoming a Detection Engineering Contractor, Part II— The PreparationYou want to become a contractor or an independent consultant in the Detection Engineering (DE) space? This series is for you.A response icon1A response icon1
InDetect FYIbyAlex Teixeira·Feb 25, 2025Threat Hunting step-by-step: Collecting Web Shells 🐚 using Ephemeral BaselinesTurning a KQL hunting query into a Defender detection rule to spot unusual web server processes using simple statistics.A response icon1A response icon1