Founders Story

Why This mission matters

Sebastien and Fred have spent almost a decade together. We focused on building methods of collection and models of detection, fraud, and malicious behavior in various SIEMs.  Through founding the Global Security Practice at Splunk, our customer-focused work drove an IT troubleshooting tool into Gartner’s top SIEM, and founded a research team to continue to get deeper in customer problems. At Devo, we built the first security product (SIEM) at Devo, focusing on the operators, detection content and intuitive operation. Over time, we have done massive amounts of research on Threat Intelligence, open source product contribution, Detection content creation, Adversary techniques application, machine-learning model crafting and building innovative methods to defend against industry-level threats.

We started this project to revolutionize a problem SIEM vendors had validating their detections worked for their customers.  In essence, we realized we had contributed to a problem now plaguing the industry. Customers always asked a very simple question we could not answer well enough, “How do you know this detection will catch bad guys?”. The SIEMs we were building and the service providers we supported,  could not measure their detections or responses to threats.

In response to this, we created an engine to generate any type of attack, simple or nation-state-level campaign, model poisoning attacks, you name it. Using a descriptive language to describe attack behaviors, we generated events in defensive technologies agnostic of the technology itself to see how the detection ecosystem performed. Through our efforts collaborating with DoD, we battle-tested our concept in one of the most sophisticated environments in the world.  The concepts behind Detecteam were born in the fire of some of the most demanding ecosystems in the world. Now, we have made the support of that mission, Detecteam.

[contact-form-7 id=”f245613″ title=”Newsletter”]

T1003.001 – LSASS Memory T1005 – Data from Local Syste T1012 – Query Registry T1016 – System Network Configuration Discovery T1018 – Remote System Discovery T1021.001 – Remote Desktop Protocol T1021.002 – SMB/Windows Admin Shares T1021.004 – SSH T1027 – Obfuscated Files or Information T1033 – System Owner/User Discovery T1036.005 – Masquerading: Match Legitimate Name or Location T1041 – Exfiltration Over C2 Channel T1047 – Windows Management Instrumentation T1053.005 – Scheduled Task/Job: Scheduled Task T1055 – Process Injection T1057 – Process Discovery T1059 – Command Line Interface T1059.001 – Command and Scripting Interpreter: PowerShell T1059.003 – Windows Command Shell T1069 – Permission Groups Discovery T1069.001 – Local Groups T1069.002 – Domain Groups T1070.004 – File Deletion T1071 – Application Layer Protocol T1071.001 – Web Protocols T1078 – Valid Accounts T1082 – System Information Discovery T1083 – File and Directory Discovery T1087.002 – Domain Account T1105 – Ingress Tool Transfer T1110.001 – Brute Force: Password Guessing T1112 – Modify Registry T1140 – Deobfuscate/Decode Files or Information T1190 – Exploit Public-Facing Application T1204.002 – User Execution: Malicious File T1210 – Exploitation of Remote Services T1218.011 – System Binary Proxy Execution: Rundll32 T1219 – Remote Access Software T1482 – Domain Trust Discovery T1486 – Data Encrypted for Impact T1490 – Inhibit System Recovery T1518.001 – Security Software Discovery T1543.003 – Create or Modify System Process: Windows Service T1566.001 – Phishing: Spearphishing Attachment T1574.002 – DLL Side-Loading