Skip to content
Artwork for Detection Dispatch (Alex's Version)
Detection Dispatch (Alex's Version) · September 1 · 1 hr 4 min

AI Won’t Fix Your Detections. Your Linux Detection Engineer Will & also Happy Birthday, Linux 🎂

Pawel Mazur joins Detection Dispatch to talk about what happens when you stop trusting detections at face value, especially when AI is involved. From generating detection logic with an LLM to actually running the technique with EDR silencers, to bypassing rules, and digging into the telemetry underneath it, Pawel makes the case for a much more skeptical approach to detection engineering. In this episode we get into: • What AI generated detection actually looks like in practice and what happens when you test it against real activity • Why AI generated detection logic can look completely correct and still fail • What happens when you actually test a detection against adversarial behavior instead of trusting the query • Why “don’t write code you cannot own” is an important rule for detection engineers using AI • How purple teaming and offensive experimentation expose detection gaps that research and vendor content can miss • Why Linux requires a different level of curiosity when you are trying to understand how attacks actually generate telemetry • How a seemingly simple detection can be bypassed by changing filenames, paths, or the way a technique is executed • Why the telemetry you think you have is not necessarily the telemetry you can actually hunt • What auditd and eBPF can reveal when your existing EDR telemetry does not tell the whole story • Where AI can genuinely help detection engineers today and where the hype is getting ahead of the tech The big picture is: “If you did not run it, break it, and understand the telemetry it produced, how do you actually know your detection works?” Links shared (practical linux detections + resources): https://for577.com/audit-mvp https://github.com/neo23x0/auditd Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

0:00-1:04:00

transcript

No transcript — this publisher did not publish one.

show notes

Pawel Mazur joins Detection Dispatch to talk about what happens when you stop trusting detections at face value, especially when AI is involved. From generating detection logic with an LLM to actually running the technique with EDR silencers, to bypassing rules, and digging into the telemetry underneath it, Pawel makes the case for a much more skeptical approach to detection engineering.

In this episode we get into:

• What AI generated detection actually looks like in practice and what happens when you test it against real activity

• Why AI generated detection logic can look completely correct and still fail

• What happens when you actually test a detection against adversarial behavior instead of trusting the query

• Why “don’t write code you cannot own” is an important rule for detection engineers using AI

• How purple teaming and offensive experimentation expose detection gaps that research and vendor content can miss

• Why Linux requires a different level of curiosity when you are trying to understand how attacks actually generate telemetry

• How a seemingly simple detection can be bypassed by changing filenames, paths, or the way a technique is executed

• Why the telemetry you think you have is not necessarily the telemetry you can actually hunt

• What auditd and eBPF can reveal when your existing EDR telemetry does not tell the whole story

• Where AI can genuinely help detection engineers today and where the hype is getting ahead of the tech

The big picture is: “If you did not run it, break it, and understand the telemetry it produced, how do you actually know your detection works?”

Links shared (practical linux detections + resources):

Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

links2