Automated threat-intelligence. Human-accountable detection.
Operational cyber intelligence from the DevSecOpsDad lab.
DevSecOpsDadAttack bridges the gap between threat intelligence and detection engineering. Each article focuses on extracting operational signal from emerging threats and translating it into practical detection opportunities defenders can validate, deploy, and improve.
Threat Intelligence
-
Threat Intel Threat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Tuesday, September 1, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Monday, August 31, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Sunday, August 30, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Saturday, August 29, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Friday, August 28, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Thursday, August 27, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Wednesday, August 26, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More]
Detection Engineering
-
Detection Eng Detection Engineering Brief - Wednesday, September 2, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Tuesday, September 1, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Monday, August 31, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Sunday, August 30, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Saturday, August 29, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Thursday, August 27, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Wednesday, August 26, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Monday, August 24, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More]
KQL Detection of the Week
-
KQL Detections KQL Detection of the Week: The String Is Not the Thing
Detecting Metadata SSRF When the Attacker Owns the Hostname, Normalising IP Obfuscation Instead of Enumerating It, and Why an Empty SHA256 Doesn't Mean Unsigned
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Field That Wasn't There
Detecting Telegram Session Theft When FileRead Doesn't Exist, Teams Phishing When ExternalAccess Isn't Populated, and Why the Best Detection This Week Is One That Checks Its Own Telemetry
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Query That Wrote Itself Eight Times
Detecting SharePoint RCE When the Brief Wrote the Same Query All Week, the Correlation Has No Anchor, and the Best Detection in the Stack Is a Baseline
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: Sins of the Grandfather
Detecting npm Lifecycle Worms When the Payload Is Two Generations Down and the C2 Is a Public Blockchain
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: A Heap of Trouble
Detecting Spring Boot Heapdump Theft When the Exfiltration Is a GET Request
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: A Meeting in 2050
Detecting Project CAV3RN's Outlook Calendar C2 and DNS AAAA Recovery Channel
By DevSecOpsDadThere is a meeting on your calendar for 13 May 2050. Nobody will ever attend it. Nobody has ever scrolled there — a quarter-century out, in a fixed one-hour window between 22:00 and 23:00 UTC, parked in the most-synced, least-read database in... [Read More] -
KQL Detections KQL Detection of the Week: The Dog That Didn't Bark
Detections built around the thing that should have happened and didn't
By DevSecOpsDadThis week’s six briefs produced 29 KQL candidates (the Friday automation decided to take a personal day) across continued Flowise CSV-agent exploitation, a GigaWiper destructor, HTML phishing from first-time external senders, live internet scanning for exposed MCP servers and AI assistant credentials,... [Read More] -
KQL Detections KQL Detection of the Week: Nice Costume, Wrong Address
Watching a disguise, then checking the one fact the disguise can't fake
By DevSecOpsDadThis week’s seven briefs produced 27 KQL candidates across a Vidar-plus-XMRig malvertising wave hiding behind a forged code-signing certificate and a 491 MB null-byte suit, device-code phishing that sails straight past URL filters, an SMB session quietly upgraded into Meterpreter, a Peyara Remote... [Read More]