Detection engineering, in the open

Security notes, written in daylight.

Hi, I'm Agron. I break and rebuild things in cybersecurity and write about it here. Mostly blue and purple team work: detection engineering, attack simulation, and whatever else catches my interest. Nothing too crazy, hope you enjoy the rants.

Latest

My blog is inside my SIEM

Every request to this site/blog lands in my homelab SIEM. The full Cloudfront to Splunk pipeline, some AWS gotchas, and what I actually detect.

#detection#splunk#aws#cloudfront
Read the post →

More posts

Browse the blog →