SOC & DETECTION ENGINEERING ARSENAL // CLIENT-SIDE EXECUTION
Operator & Detection Tradecraft Lab
ZERO-TELEMETRY LEAKAGE // 100% IN-BROWSER PARSING
Tactical engineering utilities designed for senior SOC analysts, detection engineers, and red teamers: convert Sigma rules into 4 enterprise SIEM dialects with verified AST logic, review dual-perspective LOLBAS commands mapped directly to defensive hunting queries, and run Atomic Red Team probe scripts to test EDR sensor coverage.
LIVE AST DETECTION TRANSPILER
Transpile Sigma YAML detection logic into production queries for Splunk, Sentinel, LogScale, and Elastic.
PRESETS:
SIGMA RULE SPECIFICATION (.YAML)
LEVEL: high|CATEGORY: process_creation|TAGS: attack.command-and-control, attack.t1105
index=windows (EventCode=4688 OR (source="*Sysmon*" EventCode=1))
| table _time, host, User, Image, CommandLine, ParentImage
| sort - _timeFIELD RESOLUTION & PIPELINE CONSTRAINTS:
- Targeting Windows 4688 or Sysmon Event 1 process launches.