Stop Writing Rules. Start Engineering Detections!
In this video, we cover the full detection engineering lifecycle from first principles โ past, present, and future โ and where the discipline is heading in 2026. ๐ The evolution of detection: from the 1971 Creeper worm to modern EDR, Sigma, and YARA ๐ The 6-phase detection engineering lifecycle most SOC teams have never seen ๐ Why "write once, deploy everywhere" is a syntax promise โ not an operational one ๐ Detection-as-Code: version control, CI/CD pipelines, peer review, and automated rollback ๐ Why the MGM breach was a detection engineering failure โ and what it tells us about identity as the new attack surface ๐ AI-augmented vs agentic detection: what's real today, what's coming, and what AI cannot replace โ๏ธ Accompanying blog article: https://kravensecurity.com/detection-engineering-lifecycle/ =============================================== ๐ฌ Join our Discord to carry on the conversation: https://discord.com/invite/gSMt5CRDdX ๐น๏ธ Check out our other videos: https://www.youtube.com/@adamgoss-kraven?sub_confirmation=1 ๐ซ Find more cyber threat intelligence, threat hunting, and custom tooling content at https://kravensecurity.com/ ๐ช Book a coaching session today https://kravensecurity.com/services/ 00:00 Introduction 02:30 The EDR era 03:01 YARA & Sigma 03:44 The 6-phase detection engineering lifecycle 06:20 Rule writing vs detection engineering: there's a difference 06:48 Sigma rule walkthrough 07:37 Detection-as-Code 10:00 Case study: The MGM Resorts breach 11:05 Identity is the new attack surface 11:39 AI-augmented detection: what's real and shipping today 13:33 The future of detection engineering roles 14:00 Wrap-up & next steps
Download
0 formatsNo download links available.