Skip to content
View the-d3fender's full-sized avatar

Block or report the-d3fender

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
the-d3fender/README.md

the-d3fender

stats-default

Detection Engineering | Telemetry Architecture & Detection-as-Code | Application Security | DevSecOps

I design, validate, and automate high-fidelity detection logic and telemetry pipelines. My work focuses on bridging threat intelligence with software engineering principles, transforming adversary TTP research into tested, continuous Detection-as-Code (DaC) infrastructure.


Core Technical Focus

Category Primary Focus & Tooling
Detection Logic Sigma, YARA, KQL, SPL, Falco, Suricata
Telemetry & Logging OS-level Telemetry (ETW, Sysmon, eBPF, Auditd), Log Pipelines
Automation & CI/CD Detection Rule Linting, Unit Testing (Pytest), GitHub Actions
Validation & Hunting Threat Emulation (Atomic Red Team), MITRE ATT&CK Mapping
Security Testing Penetration Testing, Red Teaming, Purple Teaming

Engineering Principles

  1. High-Signal Quality: Detection logic must provide actionable context and prioritize low false-positive rates over alert volume.
  2. Detection-as-Code: Rules are version-controlled, peer-reviewed, tested against telemetry datasets, and deployed via CI/CD.
  3. Telemetry-Driven: Effective coverage begins by engineering the underlying event streams before writing detection logic.

Verification & Contact

  • Professional Identity: the-d3fender/ across technical platforms
  • Publications & Research: Research Files

Pinned Loading

  1. hack-report-client hack-report-client Public

    Client side of Hack Report SaaS, designed with Zero Trust architecture.

    TypeScript 1

  2. Bumbleous Bumbleous Public

    Machine operator AI technology for any vehicle.

    Python

  3. net_probe net_probe Public

    Net Probe is a Python program that allows you to scan all devices connected to your local network. It can identify the IP address of each device and determine if any ports are open, helping you to …

    Python 1

  4. SpamGuard-Pro SpamGuard-Pro Public

    SpamGuard Pro: A foundational reference for spam detection using scikit-learn and Python. Leverage machine learning with a sophisticated prototype under the GNU General Public License v3.0.

    Python

  5. PyNetSniffer PyNetSniffer Public

    PyNetSniffer is a simple Python script designed to scan a range of IP addresses within a specified network to identify live hosts.

    Python

  6. attack_range attack_range Public

    Forked from splunk/attack_range

    A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

    Jinja