Hello, whoami and why I keep a detection diary
Welcome to Detection Diary. I’m Agron, and this is where I write up the security work I actually do, in my own plain terms, with the details left in there most of the time if I can remember .
A little background
I work in cybersecurity and like to fidget with all things across detection engineering, purple teaming, security research, even security engineering (gotta learn ‘em all). I have a tiny homelab consisting of a Lenovo Thinkcentre, and a M1 Mac Mini which does enough for helping me come up with different things to try and get telemetry for. I’ll share more about my homelab likely in later posts.
I mainly utilize Splunk as my SIEM and have quite a bit of knowledge of their Enterprise Security suite and how it works. There will be many posts here that utilize SPL as my main form of detection output. However, I will try to explain how I get to each detection so this should theoretically work across other SIEMs as well.
I merged my way into “cybersecurity” at a pretty young age. Back then it was a lot of googling, reverse engineering, dev tools, Java, and more googling. Cant forget all the fun Cheat Engine game memory hacking.

The “AI” we see today wasn’t so relevant back in the day so having to adopt to its use now still feels a little weird. While it may still be controversial for some, I think there are definitely some pretty cool use cases that it can be used for edpecially in the security landscape and we will explore some of those in my future posts.
What this blog is for
Theres a lot of security writing that stops at the scary headline. I want to do the opposite: I want to show the work and show the steps to get to my conclusion. Expect posts on
- Detection engineering: real SPL, how I test it, and how I cut false positives.
- Cloud and homelab creation/hardening: setting up homelabs for deteciton engineering but also for purple team validations.
- Security Researching: Sometimes theres some pretty awesome stuff out there and its cool to think and talk about it.
- Endpoint Stuff: I really like doing deep dives on how some operating systems work. I want to spend some time learning macOS at a deeper level as well as some of the newer Linux kernel stuff. Windows is Windows, but there are some cool techniques on there also.
- Lots of random cybersecurity and maybe some tech thoughts: There may be some posts that may not fit the above points, and also may be just rants about things.
Whenever I can, I’ll be creating posts that will have worked examples, not just opinions, (but i’ll litter a lot of these with my opinions).
Built the way it is written about
This site is itself a pretty small case study. It is a static build served from AWS with S3. Everything about how this site is setup and built, including CI/CD, is routed into the SIEM in my homelab so I can create alerts, and look for interesting things.
Ok, thats it for now, i’ve yapped long enough. If you want to connect with me, the best place would probably be LinkedIn for now - https://www.linkedin.com/in/agrongemajli
Thanks for reading - more soon.