Automated threat-intelligence. Human-accountable detection.
Operational cyber intelligence from the DevSecOpsDad lab.
DevSecOpsDadAttack bridges the gap between threat intelligence and detection engineering. Each article focuses on extracting operational signal from emerging threats and translating it into practical detection opportunities defenders can validate, deploy, and improve.
Threat Intelligence
-
Threat Intel Threat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Friday, October 2, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Thursday, October 1, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Wednesday, September 30, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Tuesday, September 29, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Monday, September 28, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Sunday, September 27, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More] -
Threat Intel Threat Intelligence Brief - Saturday, September 26, 2026
Operational threat reporting for defenders who need signal, not noise.
By DevSecOpsDadThreat Radar [Read More]
Detection Engineering
-
Detection Eng Detection Engineering Brief - Sunday, October 4, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Saturday, October 3, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Friday, October 2, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Thursday, October 1, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Wednesday, September 30, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Tuesday, September 29, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Monday, September 28, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More] -
Detection Eng Detection Engineering Brief - Sunday, September 27, 2026
Threat intelligence translated into detection engineering action.
By DevSecOpsDadDetection Engineering Summary [Read More]
KQL Detection of the Week
-
KQL Detections KQL Detection of the Week: The Activity Log Is Not the Activity
Why Three of Six Storm-3168 Detections Hunt for Events AzureActivity Never Records, Making BPFDoor Detection Survive a Rename, and Why split(ResourceId, '/')[6] Isn't the Resource Type
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Stage Is Not the Chain
Chaining Identity Attack Stages into a Single Detection, Fixing a Fragile IP Extraction in LLM Credential Farming, and Why max('high', 'medium') Returns 'medium'
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Character Is Not the Payload
Detecting ASCII Smuggling by Codepoint Range Instead of Character List, Decoding the Unicode Tag Block Back to Its Hidden ASCII, and Why 'MQTT Port' Isn't 'MQTT Traffic'
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The String Is Not the Thing
Detecting Metadata SSRF When the Attacker Owns the Hostname, Normalising IP Obfuscation Instead of Enumerating It, and Why an Empty SHA256 Doesn't Mean Unsigned
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Field That Wasn't There
Detecting Telegram Session Theft When FileRead Doesn't Exist, Teams Phishing When ExternalAccess Isn't Populated, and Why the Best Detection This Week Is One That Checks Its Own Telemetry
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: The Query That Wrote Itself Eight Times
Detecting SharePoint RCE When the Brief Wrote the Same Query All Week, the Correlation Has No Anchor, and the Best Detection in the Stack Is a Baseline
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: Sins of the Grandfather
Detecting npm Lifecycle Worms When the Payload Is Two Generations Down and the C2 Is a Public Blockchain
By DevSecOpsDad -
KQL Detections KQL Detection of the Week: A Heap of Trouble
Detecting Spring Boot Heapdump Theft When the Exfiltration Is a GET Request
By DevSecOpsDad