Interested in detection engineering: practical, explainable ways to turn ordinary network and system logs into useful leads.
Building sigwood, a local-first threat-hunting tool for Zeek, Pi-hole, syslog and the systemd journal, and CloudTrail. It sits between grep and a SIEM, and aims to show its work.
