Skip to content
Artwork for Detection Dispatch (Alex's Version)

Detection Dispatch (Alex's Version)

Alex Hurtado

Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.


Play
  • 14 episodes
  • weekly
  • Avg 51 min
  • English
  • S1 · E14
    Wednesday · 59 min

    Apple, Please Give Us More Logs feat. Patrick Wardle

    Patrick Wardle joins Detection Dispatch to explore what happens when the things we trust become the things we stop looking at. From signed and notarized applications hiding malicious dylibs to trusted processes inheriting privileges, Patrick walks through the places where macOS can look completely clean until you look underneath it. We get into dynamic library hijacking, the limitations of process level telemetry, and the detection opportunities hiding inside macOS Endpoint Security. We also explore ClickFix, rogue AI agents, and the increasingly difficult question of how to distinguish malicious behavior from legitimate activity when attackers or autonomous agents are operating through trusted software. In this episode we get into: • Why dynamic library hijacking is still alive on macOS despite years of Apple mitigations • How the 3CX supply chain attack hid malicious code inside a trusted application that was signed, notarized, and largely overlooked by security tooling • Why attackers love dylibs: stealth, inherited trust, and inherited privileges • The problem with treating the process as the atomic unit of detection when malicious code can execute inside a trusted process • Why enumerating loaded libraries on macOS is surprisingly difficult and the Endpoint Security workarounds that make it possible • How process, file, and network events can be stitched together to reveal behavior that individual events do not show • Why code signing is incredibly useful for macOS detection and why “signed” does not mean “safe” • How AI agents executing legitimate platform binaries make attribution even harder: is the behavior malicious, anomalous, user directed, or the result of a compromised agent? • Why ClickFix and clipboard to terminal execution have become such an effective macOS delivery mechanism • The huge detection opportunity hiding inside an undocumented Endpoint Security clipboard event • What makes Objective by the Sea different and why building a strong Apple security community matters just as much as the research Objective by the Sea: https://objectivebythesea.com/ Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E13
    September 10 · 44 min

    Bill Gates’ AI Manifesto, Stolen LLMs & AI Honeypots feat. Eli Woodward

    Eli Woodward joins Detection Dispatch to explore what happens when AI becomes both the thing we're building and the thing we're trying to detect. From a Christmas AWS honeypot experiment that turned into a global network of AI honeypots to millions of captured prompts, Eli walks through what attackers are actually doing with exposed AI infrastructure and what those behaviors reveal about the detection challenges ahead. We get into LLM jacking, stolen compute, malicious prompts, AI agents, and the increasingly difficult question of whether an action was taken by a human, an agent, or an attacker. We also dig into what changes when AI moves from answering questions to actually taking action and what that means for detection engineering. In this episode we get into: • How Eli's AI honeypots became a window into real-world AI abuse • What attackers are doing with exposed AI infrastructure and stolen compute • Detecting the difference between human-driven and agent-driven behavior • Why timing, sequencing, and context may become critical AI detection signals • What changes when an AI moves from knowledge worker to autonomous actor • Why AI security needs the same grounding, evaluation, and guardrails that modern detection engineering does • What happens to detection engineering as agents start doing the work themselves • And where humans may still have an advantage: judgment, taste, curation, and knowing when the machine is wrong AI Honeypots: https://ai-honeypots.com/ Bill Gates' AI Manifesto: https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make The conversation also connects the latest The AI Security Engineering Skills Map, Alex's recent work with Dan Nguyen-Huu on how detection engineering and AI security engineering are increasingly becoming the same discipline. Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E12
    September 1 · 1 hr 4 min

    AI Won’t Fix Your Detections. Your Linux Detection Engineer Will & also Happy Birthday, Linux 🎂

    Pawel Mazur joins Detection Dispatch to talk about what happens when you stop trusting detections at face value, especially when AI is involved. From generating detection logic with an LLM to actually running the technique with EDR silencers, to bypassing rules, and digging into the telemetry underneath it, Pawel makes the case for a much more skeptical approach to detection engineering. In this episode we get into: • What AI generated detection actually looks like in practice and what happens when you test it against real activity • Why AI generated detection logic can look completely correct and still fail • What happens when you actually test a detection against adversarial behavior instead of trusting the query • Why “don’t write code you cannot own” is an important rule for detection engineers using AI • How purple teaming and offensive experimentation expose detection gaps that research and vendor content can miss • Why Linux requires a different level of curiosity when you are trying to understand how attacks actually generate telemetry • How a seemingly simple detection can be bypassed by changing filenames, paths, or the way a technique is executed • Why the telemetry you think you have is not necessarily the telemetry you can actually hunt • What auditd and eBPF can reveal when your existing EDR telemetry does not tell the whole story • Where AI can genuinely help detection engineers today and where the hype is getting ahead of the tech The big picture is: “If you did not run it, break it, and understand the telemetry it produced, how do you actually know your detection works?” Links shared (practical linux detections + resources): https://for577.com/audit-mvp https://github.com/neo23x0/auditd Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E11
    August 26 · 1 hr 1 min

    The Detection Factory (Loop Engineering in Practice)

    Tejas Paranjape joins Detection Dispatch to talk about what a detection factory can actually look like in practice and what changes when detection engineering becomes a repeatable, code driven production process rather than a collection of rules living in someone’s head. His Detection Factory breaks the work into specialized stages for writing, tuning, reviewing, testing, and shipping detections, with feedback and context carried through the process. In this episode we get into: • What a Detection Factory actually looks like and what each of its four stations does • Why detections, workflows, and infrastructure need to be represented as code if you want to automate the work • How to build quality gates and backtesting into the detection development process before anything gets shipped • Why context and institutional knowledge need to travel with the detection instead of living in the head of whoever built it • What happens when AI gets a detection mostly right but still misses something important, like an alternate log format • Why different models can have different jobs in the pipeline rather than asking one model to do everything • Where human review still matters, particularly when you are trying to catch the last few percent of problems • What workflows as code could mean for moving from detection to response at machine speed • The unexpected connection between PKI, identity, and detection engineering and why knowing what something actually is matters before you build detections around it The big picture is: “What would we have to build around it to make detection development repeatable, testable, reviewable, and trustworthy?” You can get started with ADEF here: https://github.com/Nebulock-Inc/agentic-detection-engineering-framework/blob/main/docs/methodology.md Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E10
    August 13 · 55 min

    Sysmon for AI Visibility feat. Anton Ovrutksy

    Anton Ovrutsky from Huntress joins Detection Dispatch to talk about ATEN, his latest open-source project to do what Sysmon did for win event telemetry to AI agents. The idea came from a pretty simple realization: as security practitioners, we’re comfortable saying “we don’t have the telemetry for that”...And there’s a LOT missing. In this episode we get into: The “what the hell did I just give Claude access to?” problem — credentials, packages, skills, and systems pile up fast when you’re just trying to get the agent to work Why process trees tell you what happened, but not what the agent was asked to do The huge blind spot around credentials living on endpoints — especially when an agent and an infostealer can touch the same credential store How ATEN connects the prompt that started an action to the endpoint activity that followed, including a session ID to tie it together Why we may need to start thinking about agents as something like an entirely new OS running on top of the endpoint The problem with trying to reconstruct an incident across endpoint + prompt transcript + network telemetry when half of that evidence was never logged How a compromised skill or dependency can turn a seemingly normal agent workflow into a supply-chain problem Why intent vs. action might become one of the most important detection primitives for agentic systems And the uncomfortable reality that we started giving AI agents autonomy before we had good visibility into what they were actually doing The question goes from “What did the agent execute?” to “What did I ask it to do, what did it actually do, and what did it have access to along the way?” That feels a lot more like the telemetry problem we should have been solving from the start. Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E9
    July 31 · 46 min

    There's No D3FEND for AI (So He Built One) feat. Edward Lee

    Quick count: MITRE ATLAS, OWASP's Top 10s, NIST AML, Cisco's framework, MAESTRO, Databricks' AI security framework..Every org says "go do AI security," startups are popping out to sel lit to you…points you at a pile of frameworks that all describe the same handful of problems in slightly different words, and leaves you to cross-reference them yourself at 11pm. Edward Lee joins Dispatch to talk about AIDEFEND: the open-source knowledge base he built to be the thing MITRE ATT&CK has and AI security doesn't: a D3FEND. One place to search across AIDEFEND and ATLAS techniques, MAESTRO threats, every OWASP Top 10, Cisco, NIST AML, type in a keyword and see how it maps everywhere at once, instead of holding nine tabs open and doing the translation in your head. In this episode we get into: "Detect" isn't one thing — it's 16+ techniques, and only three signals actually matter: prompt-level telemetry, tool call graphs, and retrieval provenance Why the retrieval layer is ground zero — if you can't say what got pulled and from where, you're not reconstructing that incident, you're guessing Rogue agents behave less like malware and more like an insider threat — legit permissions, illegitimate intent "Goal drift": when a tool call sequence takes a left turn that only makes sense if something got injected midstream The case for giving agents their own identities instead of borrowed ones — and why token usage tells you almost nothing useful Where to start logging with zero visibility today: proxy-level tool calls and API calls, before you even look at content Follow Edward's work: AIDEFEND — aidefend.net AIDEFEND on GitHub — aidefend.dev AI Defense Matrix (more executively friendly matrix) featured in the episode — https://aidefensematrix.com/ Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E8
    July 20 · 39 min

    Your Dream Job Offer Might Depend on You Cloning/Running Malicious GitHub Repos feat. Tim Peck

    The job market is shitty right now, and threat actors are exploiting exactly that. Developers are a hot target, and it cuts both ways: they'll come at you as a fake recruiter sending a "coding test" straight off GitHub, or as a fake candidate using a stolen identity to get hired and work the inside. Cloning and running a malicious repo is now just part of the interview process. Doing a human CAPTCHA to prove the person on the other end isn't AI is no longer optional. Tim Peck (Director of Research, Detections.ai) joins Dispatch to break down DEV#POPPER and the broader Contagious Interview campaign, still active, still evolving. In this episode we get into: Why this attack starts with the human and why you can't train that instinct away Word Wrap Obfuscation: hiding payloads past the edge of the screen so scrolling through the code looked clean Why devs specifically get targeted: the power-full/shell languages baked into the job function itself, affiliation with crypto wallets Fake candidate red flags: brand new LinkedIn profiles, awkward response lag, 4am emails, resume inconsistencies What detection helps assuming breach Follow Tim's work on: Detections.ai https://www.securonix.com/blog/analysis-of-devpopper-new-attack-campaign-targeting-software-developers-likely-associated-with-north-korean-threat-actors/ Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E7
    July 15 · 1 hr 4 min

    Red Team Wrote a Book on Evading You. Literally. feat. Dennis Chow & Michael LaSalvia

    Dennis Chow (Detection Engineering Director, back for round two) and Michael LaSalvia (red team lead) join Dispatch to talk about their new book, Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses, and what happens when a blue teamer and a red teamer decide to write the playbook together instead of against each other. In this episode we get into: Why off-the-shelf adversary emulation repos are dying, and why building your own evasive tooling, not just running someone else's, makes you a fundamentally better detection engineer The trusted advisor model: bringing blue teamers inside red team ops so trust replaces the us vs. them dynamic The unmodified Kali header in a packet that blew a six month long campaign Shared fate as an operating model, borrowed from cloud providers, to stop punishing one side for the other's success Go (open-source programming language aka Golang supported by Google) and cross platform payloads: why Windows only red team frameworks have difficulty in keeping up with cloud and identity based attack paths Their favorite chapters to write: low and slow exfiltration, and the hybrid packer that finally got past an EDR that wouldn't quit Follow Dennis & Michael's work on: Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses — available for pre-order on Packt and Amazon https://www.amazon.com/Evasion-Engineering-Building-Custom-Defenses-ebook/dp/B0GKDC57S8 VM setup for adversary emulation & testing: https://github.com/Orange-Cyberdefense/GOAD Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E6
    July 7 · 47 min

    What Headless Actually Means feat. Maxime Lamothe-Brassard Founder of LimaCharlie

    The definition of headless is taking shape. More software is shipping with an MCP. Teams are starting to require it in procurement. Your CLI and Claude Code can now talk directly to the tools you already run. LimaCharlie was one of the first platforms in the SOC to build everything through the command line....long before the post-Claude boom. Maxime Lamothe-Brassard (their founder) joins Dispatch to explore what going headless actually means for security operations. In this episode we get into: What headless actually means mechanically and why it's a very old computing idea security is only now fully inheriting Why the UI becoming optional levels the playing field and kills the faith-based vendor pitch The eager intern problem: permissions control what an agent is allowed to do, not whether its answer is right Why passing the MCP boundary and trusting the LLM on the other side is a front door left wide open GPT wrappers vs. real headless infrastructure: who owns the detection logic and who's just reselling tokens The customer who told their MSSP they'd rather their CEO get locked out for 30 minutes than wait on a human to respond The one thing Max won't let a headless agent do...ever Follow Max's work on: limacharlie.io | limacharlie.io/blog LinkedIn: linkedin.com/in/maximelb Free Build Your Own Headless SOC Workshop with BlackHills Infosec @ BlackHat, August 5, 2026 https://luma.com/black-hat-headless-soc-workshop?tk=crcMy4 Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E5
    June 4 · 1 hr 8 min

    Words are Cheap. Sense Making is Not..feat. Diego Perez

    What happens when a philosopher walks into a SOC? Apparently, he builds one from the ground up, spends a decade making sense of detection engineering across financial services, global IR teams, and now Canva. Diego Perez is a detection engineer who studied philosophy, taught himself security at 2am with a newborn in the other room, and has been quietly writing some of the sharpest unsloppy takes on the internet about what detection engineering actually is versus what we pretend it is. His blog Quasarops lives by one rule: words are cheap, sense making is not. We hit on: Why "garbage in, garbage out" is a heuristic that stops short of actually helping anyone The Cynefin framework and why knowing which detections you need lives in the complex domain, not the complicated one Detection as code: is it overrated now that coding agents exist, or are we asking the wrong question entirely The Red Queen effect, Jevons' paradox, and why you do actually need AI in your SOC whether you like it or not Agentic threat hunting: whose tokens do you trust, yours or a vendor's black box Why the human element is more important than ever, and who exactly gets blamed when the model gets it wrong Follow Diego's substack: https://quasarops.com Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E4
    May 30 · 37 min

    DE on Mac Finally Has a Champion. Her name is Olivia Gallucci.

    macOS detection engineering has had a documentation problem for years. Everyone told Olivia Gallucci she was locking herself into a platform nobody cared about. Then infostealers showed up, enterprise Mac fleets exploded, and suddenly her work was the most in-demand research nobody knew existed. Olivia is a security engineer at Datadog living inside macOS internals...from Apple Silicon boot chain to ESF event families to IOKit abuse....and she is single-handedly dragging macOS DE into the light. In this episode we get into: Why you can't just flag osascript anymore and what to look at instead The process tree trap that trips up every Windows-native DE who crosses over Background Task Management: the persistence metadata everyone's sleeping on Living off the Orchard binaries Why your EDR is abstracting macOS telemetry from you and what to do about it Jonathan Levin's books, Jaron Bradley's Sprite Tree, and the resources that actually matter Follow Olivia's work on: oliviagallucci.com | [ret]2read — An OS Internals Newsletter (Substack) LinkedIn: linkedin.com/in/olivia-gallucci 2026 main stage at BlackHat Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E3
    May 13 · 51 min

    GRC, the Passenger Princess of the SOC? feat. Ayoub Fandi

    GRC has been called the passenger princess of security for too long. In this episode, Alex sits down with Ayoub Fandi, GRC engineer and author of the GRC Engineer newsletter, to make the case that GRC and detection engineering are solving solving the same problems and somehow still not working together. This episode covers: Why GRC plays PvE while everyone else in security plays PvP and why that actually makes them your best ally How auditors certify 100% coverage from less than 1% of your environment Detection debt meets GRC debt: what inheriting someone else's program looks like on both sides Vibe coding, AI agents deleting production databases, and what that means for both of our jobs Ayoub's newsletter and podcast: GRCengineer.com Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E2
    May 6 · 48 min

    A DE's Guide to Staying in the Loop feat. Your Favorite Detection Engineering Instructor Hayden Covington

    Detection Dispatch (Alex's Version) episode two brings on the person who treats detection engineering like an actual craft....not a vendor feature list, not a MITRE bingo card, not a vibe coded rule you ship and forget. Hayden teaches detection engineering at Antisyphony Training and runs the SOC at Black Hills Information Security, which means he's not theorizing. He's got the reps, the scars, and even a home SIEM with documentation. This is the episode for practitioners who are watching Claude write their detections and quietly wondering if they're slowly getting worse at their job. In this episode we cover: The detection lifecycle nobody actually closes: research, write, validate and the canary step that tells you whether your thousand rules are quietly dead in the water six months from now. The CTI firehose problem. When every vendor blog is just an ad wearing a threat report costume, how do you find the gold? (Hint: DFIR Report and Google TI don't need your clicks) AI writing detections: yes, with caveats. No for junior engineers who've never written a query. And absolutely not without a review agent, an experimental pipeline, and final approval from a human who still knows how to dribble the ball. Why you cannot send AI out like a Pokémon and what happens to your detection program when you try. Find Hayden at @kilobytethedust and at antisyphontraining.com. Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

    • Transcript
  • S1 · E1
    April 28 · 35 min

    Axios, Mythos, and a Lethal Trifecta Walk Into a SOC  feat. John Hammond

    Detection Dispatch (Alex's Version) premieres with John Hammond...Huntress senior researcher, former DoD red team, the guy 2M+ people watch break attacks down in real time for the red-meets-blue conversation the week forced into existence. Alex came up blue. John came up red. They meet in the middle on the three stories eating the industry alive. In this episode we cover: Axios: one patient social engineer, a fake founder Slack workspace, and an NPM maintainer who never stood a chance. The lethal trifecta: private data, untrusted content, network egress. When all three show up in one agent, there be dragons. Why prompt injection isn't getting solved, and what that means for your MCP sprawl. Mythos + Project Glasswing The red teamer's detection wishlist Find John at @_JohnHammond, jh.live, and on Huntress's Declassified. Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

Showing 1–14 of 14 episodes