Back to Browse

Stop Writing Rules. Start Engineering Detections!

335 views
May 18, 2026
15:09

In this video, we cover the full detection engineering lifecycle from first principles โ€” past, present, and future โ€” and where the discipline is heading in 2026. ๐Ÿ“Œ The evolution of detection: from the 1971 Creeper worm to modern EDR, Sigma, and YARA ๐Ÿ“Œ The 6-phase detection engineering lifecycle most SOC teams have never seen ๐Ÿ“Œ Why "write once, deploy everywhere" is a syntax promise โ€” not an operational one ๐Ÿ“Œ Detection-as-Code: version control, CI/CD pipelines, peer review, and automated rollback ๐Ÿ“Œ Why the MGM breach was a detection engineering failure โ€” and what it tells us about identity as the new attack surface ๐Ÿ“Œ AI-augmented vs agentic detection: what's real today, what's coming, and what AI cannot replace โœ๏ธ Accompanying blog article: https://kravensecurity.com/detection-engineering-lifecycle/ =============================================== ๐Ÿ’ฌ Join our Discord to carry on the conversation: https://discord.com/invite/gSMt5CRDdX ๐Ÿ“น๏ธ Check out our other videos: https://www.youtube.com/@adamgoss-kraven?sub_confirmation=1 ๐Ÿซ Find more cyber threat intelligence, threat hunting, and custom tooling content at https://kravensecurity.com/ ๐Ÿ’ช Book a coaching session today https://kravensecurity.com/services/ 00:00 Introduction 02:30 The EDR era 03:01 YARA & Sigma 03:44 The 6-phase detection engineering lifecycle 06:20 Rule writing vs detection engineering: there's a difference 06:48 Sigma rule walkthrough 07:37 Detection-as-Code 10:00 Case study: The MGM Resorts breach 11:05 Identity is the new attack surface 11:39 AI-augmented detection: what's real and shipping today 13:33 The future of detection engineering roles 14:00 Wrap-up & next steps

Download

0 formats

No download links available.

Stop Writing Rules. Start Engineering Detections! | NatokHD