Brendan Chamberlain
@infosecb
Followers
1K
Following
2K
Media
16
Statuses
483
Threat Detection Engineer | detection & response | automation | macOS security | awesome-detection-engineering, LOOBins, Rulehound
Joined February 2016
Today I'd like to share a tool I recently wrote called Rulehound. It's a detection ruleset catalogue and search engine containing over 7,500 rules from 5 distinct sources. More details in thread. https://t.co/IYOnv1ucy0
9
34
160
If you ever wondered what goes into merging a Sigma rule in the @sigma_hq repo, check out the latest blog. SigmaHQ Quality Assurance Pipeline - https://t.co/A2OuF1VOcw We delve into the process we go through to ensure the community contributed rules are up to par.
1
10
25
1
7
15
My heart goes out to all the families and individuals anxious over their futures following the abrupt and chaotic announcement of H-1B visa changes. America should be working to attract more skilled talent, not create uncertainly that turns them away. To all legal immigrants
592
556
7K
I spent some time with Spec Kit today to bootstrap a small side project and I’m impressed. It’s worth a look if you want to take vibe coding to the next level. Has me thinking about how a framework like this could be applied to Detection Engineering. https://t.co/mrctgLZcz5
github.blog
Developers can use their AI tool of choice for spec-driven development with this open source toolkit.
0
0
2
Not unexpected “Velociraptor incident response tool abused for remote access” https://t.co/TXZcTE49tR
news.sophos.com
This approach represents an evolution from threat actors abusing remote monitoring and management tools
3
14
47
wiz.io
Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
😱Imagine waking up to see all your private github repositories were published publicly ... That's what happened overnight for >400 users/orgs and >5000 repositories s1ngularity (the Nx supply chain attack) continues to bear fruit for attackers. Rotate ASAP!
0
2
12
The "Detection Engineering Field Manual" earned a spot on awesome-detection-engineering. This one's worth a read for both aspiring and experienced detection engineers alike. Looking forward to future posts. https://t.co/TdyDqgmwlW
https://t.co/x71xnRF3OL
0
0
10
🇻🇳 VNPT ( https://t.co/WFS8XBWNzt) victime d'une #cyberattaque autour du 15 avril 2025. ⏭️ https://t.co/OIZudqzvVQ 👉 https://t.co/d8KqCPFg6c cc @ransomwaremap @cyber_etc
vietnamnet.vn
Hackers gain access to editorial systems, threatening news integrity and safety.
0
3
2
72 ⭐️ Rulehound is a comprehensive index and searchable repository of open-source threat detection rulesets across multiple security platforms 🛡️ to accelerate detection engineering workflows. @infosecb
https://t.co/e6cG63O8Wh
#starhistory #GitHub #OpenSource
0
1
1
Now I can finally say I've written about a topic Gartner, Forrester or @anton_chuvakin haven't covered before when it comes to #SIEM! https://t.co/T4RzbYy7ek
#DetectionEngineering
detect.fyi
What should drive picking one detection idea over another?
0
7
14
Sublime's email-specific threat detection ruleset is now available in Rulehound:
0
0
3
I wrote a post on #macOS internals for detection engineers! 🔎 In this post, I focus on versioning quirks, system logging, and the historical context of macOS security features. I'd love to do a series on this soon—focusing on how I learned ARM basics, and how folks from
5
24
127
Lastly, I’m looking to expand the ruleset sources. If you would like me to include one, please submit an issue.
0
0
3
Rulehound is nowhere near done. There are a few known bugs and most likely some issues that I wasn’t able to identify during testing. Please submit any bugs you find in the Rulehound Github repo.
0
0
1
Why Rulehound? As Detection Engineers, we oftentimes turn to the amazing free and publicly available rulesets for inspiration when developing new content. Why reinvent the wheel when there’s already a blueprint? It’s a challenge to search across all the various rulesets for a
0
0
4