infosecb Profile Banner
Brendan Chamberlain Profile
Brendan Chamberlain

@infosecb

Followers
1K
Following
2K
Media
16
Statuses
483

Threat Detection Engineer | detection & response | automation | macOS security | awesome-detection-engineering, LOOBins, Rulehound

Joined February 2016
Don't wanna be here? Send us removal request.
@infosecb
Brendan Chamberlain
7 months
Today I'd like to share a tool I recently wrote called Rulehound. It's a detection ruleset catalogue and search engine containing over 7,500 rules from 5 distinct sources. More details in thread. https://t.co/IYOnv1ucy0
9
34
160
@nas_bench
Nasreddine Bencherchali
3 days
If you ever wondered what goes into merging a Sigma rule in the @sigma_hq repo, check out the latest blog. SigmaHQ Quality Assurance Pipeline - https://t.co/A2OuF1VOcw We delve into the process we go through to ensure the community contributed rules are up to par.
1
10
25
@infosecb
Brendan Chamberlain
1 month
Thanks to a poorly timed nor’easter, my flight to #OBTS was canceled. Bummed to be missing it but I hope to try again next year!
@infosecb
Brendan Chamberlain
4 months
After many failed attempts, I’m thrilled to share that I’ll finally be attending #OBTS this year! See you in Ibiza 😎🏝️
1
0
1
@theevilbit
Csaba Fitzl
1 month
We are doing #obts10k run again at @objective_see #obts, so pack your running shoes to Ibiza 😎
1
7
15
@AndrewYNg
Andrew Ng
2 months
My heart goes out to all the families and individuals anxious over their futures following the abrupt and chaotic announcement of H-1B visa changes. America should be working to attract more skilled talent, not create uncertainly that turns them away. To all legal immigrants
592
556
7K
@infosecb
Brendan Chamberlain
2 months
I spent some time with Spec Kit today to bootstrap a small side project and I’m impressed. It’s worth a look if you want to take vibe coding to the next level. Has me thinking about how a framework like this could be applied to Detection Engineering. https://t.co/mrctgLZcz5
Tweet card summary image
github.blog
Developers can use their AI tool of choice for spec-driven development with this open source toolkit.
0
0
2
@HackingLZ
Justin Elze
2 months
Not unexpected “Velociraptor incident response tool abused for remote access” https://t.co/TXZcTE49tR
Tweet card summary image
news.sophos.com
This approach represents an evolution from threat actors abusing remote monitoring and management tools
3
14
47
@0x4D31
Adel Ka
3 months
Tweet card summary image
wiz.io
Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
@ramimacisabird
Rami McCarthy
3 months
😱Imagine waking up to see all your private github repositories were published publicly ... That's what happened overnight for >400 users/orgs and >5000 repositories s1ngularity (the Nx supply chain attack) continues to bear fruit for attackers. Rotate ASAP!
0
2
12
@infosecb
Brendan Chamberlain
4 months
After many failed attempts, I’m thrilled to share that I’ll finally be attending #OBTS this year! See you in Ibiza 😎🏝️
1
0
3
@MenInBlazers
Men in Blazers
4 months
And you won. Up The Green 🌲
@VermontGreenFC
Vermont Green FC
4 months
We're going to PKs.
7
17
233
@HackingLZ
Justin Elze
4 months
Bump
@HackingLZ
Justin Elze
4 years
Quarterly reminder find hobbies outside of InfoSec if you’re in this for the long haul.
13
14
125
@infosecb
Brendan Chamberlain
5 months
The "Detection Engineering Field Manual" earned a spot on awesome-detection-engineering. This one's worth a read for both aspiring and experienced detection engineers alike. Looking forward to future posts. https://t.co/TdyDqgmwlW https://t.co/x71xnRF3OL
0
0
10
@StarHistoryHQ
Star History
6 months
72 ⭐️ Rulehound is a comprehensive index and searchable repository of open-source threat detection rulesets across multiple security platforms 🛡️ to accelerate detection engineering workflows. @infosecb https://t.co/e6cG63O8Wh #starhistory #GitHub #OpenSource
0
1
1
@ateixei
Alex Teixeira
7 months
Now I can finally say I've written about a topic Gartner, Forrester or @anton_chuvakin haven't covered before when it comes to #SIEM! https://t.co/T4RzbYy7ek #DetectionEngineering
Tweet card summary image
detect.fyi
What should drive picking one detection idea over another?
0
7
14
@infosecb
Brendan Chamberlain
7 months
Sublime's email-specific threat detection ruleset is now available in Rulehound:
0
0
3
@OliviaGalluccii
Olivia Gallucci ✨
7 months
I wrote a post on #macOS internals for detection engineers! 🔎 In this post, I focus on versioning quirks, system logging, and the historical context of macOS security features. I'd love to do a series on this soon—focusing on how I learned ARM basics, and how folks from
5
24
127
@infosecb
Brendan Chamberlain
7 months
Lastly, I’m looking to expand the ruleset sources. If you would like me to include one, please submit an issue.
0
0
3
@infosecb
Brendan Chamberlain
7 months
Rulehound is nowhere near done. There are a few known bugs and most likely some issues that I wasn’t able to identify during testing. Please submit any bugs you find in the Rulehound Github repo.
0
0
1
@infosecb
Brendan Chamberlain
7 months
Why Rulehound? As Detection Engineers, we oftentimes turn to the amazing free and publicly available rulesets for inspiration when developing new content. Why reinvent the wheel when there’s already a blueprint? It’s a challenge to search across all the various rulesets for a
0
0
4