Detection Engineering: Because your “Next-Gen” AI is just an expensive random number generator

Hello. If you are reading this, you are probably from DCG420, or you are lost on the internet. Either way, sit down.

We need to talk about Detection Engineering (DE). I saw my notes from the presentation (the PDF is attached if you want to see my bad handwriting). I wrote “is it a sport?” No. Sport is healthy. Detection Engineering is just sitting in a dark room trying to find out why your “best loc” (best-in-class, as the sales guys say with straight face) firewall didn’t see the hacker who is currently downloading your entire database using a script a teenager wrote in 5 minutes.

What is Detection Engineering? (The “No Bullsh*t” Edition)

In the industry, they tell you DE is “proactive security posture.” In reality, DE is the art of admitting your environment is a disaster and trying to build a tripwire before the house burns down.

My notes ask: “Is it for us?” If you have a computer and it is connected to the internet, then yes, it is for you. Unless you like being a charity for ransomware groups. They need new Ferraris too, I guess.

HEFAISTOS: Not a “Solution,” a Hammer.

We are building HEFAISTOS. Why? Because we looked at current tools and realized they are built for people who like clicking buttons and looking at pretty charts that mean nothing.

HEFAISTOS is a forge. It is for Engineering. We don’t do “magic.” We do detections based on threats, not based on what a marketing department in California thinks is “cool.” We take your “four cuivanat” (your messy environments) and we actually look at what is happening inside.

Why DCG420?

Because if you try to do DE alone, you will start talking to your logs. We do this as a collective. We share the pain. We share the code. We make sure that when the “Dostoy” (destruction) comes, we are the ones holding the hammer, not the ones being the nail.

Go back to work. Or don’t. Your logs will be there waiting to be ignored.