Detection Dispatch (Alex's Version)

Detection Dispatch (Alex's Version)

Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

Episodes

October 7, 2026 • 44 mins

Tobias Castleberry joins Dispatch to answer a question: is a detection engineering certification actually worth it?

With detection engineering certifications still few and far between, Tobias breaks down his experience taking the CJDE from the perspective of someone already doing the work. We get into the training, the labs, the exam, failing the first attempt, and what changed the second time around.

But the bigger conversation is a...

Listen
Watch
Mark as Played

Andrew Morris joins Detection Dispatch to explore what happens when lying to attackers becomes one of the best ways to detect them.

From GreyNoise sensors watching the internet at scale to Project Swarm turning real attacker traffic into data detection engineers can actually use, Andrew walks through why deception is having a moment. We get into honeypots, PCAPs, vulnerability exploitation, and what changes when attackers get better...

Listen
Watch
Mark as Played

Patrick Wardle joins Detection Dispatch to explore what happens when the things we trust become the things we stop looking at.

From signed and notarized applications hiding malicious dylibs to trusted processes inheriting privileges, Patrick walks through the places where macOS can look completely clean until you look underneath it.

We get into dynamic library hijacking, the limitations of process level telemetry, and the detection o...

Listen
Watch
Mark as Played

Eli Woodward joins Detection Dispatch to explore what happens when AI becomes both the thing we're building and the thing we're trying to detect.

From a Christmas AWS honeypot experiment that turned into a global network of AI honeypots to millions of captured prompts, Eli walks through what attackers are actually doing with exposed AI infrastructure and what those behaviors reveal about the detection challenges ahead.

We get into LL...

Listen
Watch
Mark as Played

Pawel Mazur joins Detection Dispatch to talk about what happens when you stop trusting detections at face value, especially when AI is involved. From generating detection logic with an LLM to actually running the technique with EDR silencers, to bypassing rules, and digging into the telemetry underneath it, Pawel makes the case for a much more skeptical approach to detection engineering.

In this episode we get into:

• What AI generat...

Listen
Watch
Mark as Played

Tejas Paranjape joins Detection Dispatch to talk about what a detection factory can actually look like in practice and what changes when detection engineering becomes a repeatable, code driven production process rather than a collection of rules living in someone’s head. His Detection Factory breaks the work into specialized stages for writing, tuning, reviewing, testing, and shipping detections, with feedback and context car...

Listen
Watch
Mark as Played

Anton Ovrutsky from Huntress joins Detection Dispatch to talk about ATEN, his latest open-source project to do what Sysmon did for win event telemetry to AI agents. The idea came from a pretty simple realization: as security practitioners, we’re comfortable saying “we don’t have the telemetry for that”...And there’s a LOT missing.

In this episode we get into:

  • The “what the hell did I just give ...
Listen
Watch
Mark as Played

Quick count: MITRE ATLAS, OWASP's Top 10s, NIST AML, Cisco's framework, MAESTRO, Databricks' AI security framework..Every org says "go do AI security," startups are popping out to sel lit to you…points you at a pile of frameworks that all describe the same handful of problems in slightly different words, and leaves you to cross-reference them yourself at 11pm.

Edward Lee joins Dispatch to talk about AIDEFEND: the open-source ...

Listen
Watch
Mark as Played

The job market is shitty right now, and threat actors are exploiting exactly that. Developers are a hot target, and it cuts both ways: they'll come at you as a fake recruiter sending a "coding test" straight off GitHub, or as a fake candidate using a stolen identity to get hired and work the inside. Cloning and running a malicious repo is now just part of the interview process. Doing a human CAPTCHA to prove the person on the other...

Listen
Watch
Mark as Played

Dennis Chow (Detection Engineering Director, back for round two) and Michael LaSalvia (red team lead) join Dispatch to talk about their new book, Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses, and what happens when a blue teamer and a red teamer decide to write the playbook together instead of against each other.

In this episode we get into:

  • Why off-the-shelf adversary emulation repos are dying, and ...
Listen
Watch
Mark as Played

The definition of headless is taking shape. More software is shipping with an MCP. Teams are starting to require it in procurement. Your CLI and Claude Code can now talk directly to the tools you already run.

LimaCharlie was one of the first platforms in the SOC to build everything through the command line....long before the post-Claude boom. Maxime Lamothe-Brassard (their founder) joins Dispatch to explore what going headless actua...

Listen
Watch
Mark as Played

What happens when a philosopher walks into a SOC? Apparently, he builds one from the ground up, spends a decade making sense of detection engineering across financial services, global IR teams, and now Canva. 

Diego Perez is a detection engineer who studied philosophy, taught himself security at 2am with a newborn in the other room, and has been quietly writing some of the sharpest unsloppy takes on the internet about w...

Listen
Watch
Mark as Played

macOS detection engineering has had a documentation problem for years. Everyone told Olivia Gallucci she was locking herself into a platform nobody cared about. Then infostealers showed up, enterprise Mac fleets exploded, and suddenly her work was the most in-demand research nobody knew existed.

Olivia is a security engineer at Datadog living inside macOS internals...from Apple Silicon boot chain to ESF event families to IOKit abuse...

Listen
Watch
Mark as Played

GRC has been called the passenger princess of security for too long. In this episode, Alex sits down with Ayoub Fandi, GRC engineer and author of the GRC Engineer newsletter, to make the case that GRC and detection engineering are solving solving the same problems and somehow still not working together.

This episode covers:

  • Why GRC plays PvE while everyone else in security plays PvP and why that actually makes them your best ally
  • ...
Listen
Watch
Mark as Played

Detection Dispatch (Alex's Version) episode two brings on the person who treats detection engineering like an actual craft....not a vendor feature list, not a MITRE bingo card, not a vibe coded rule you ship and forget. Hayden teaches detection engineering at Antisyphony Training and runs the SOC at Black Hills Information Security, which means he's not theorizing. He's got the reps, the scars, and even a home SIEM with documentati...

Listen
Watch
Mark as Played

Detection Dispatch (Alex's Version) premieres with John Hammond...Huntress senior researcher, former DoD red team, the guy 2M+ people watch break attacks down in real time for the red-meets-blue conversation the week forced into existence. Alex came up blue. John came up red. They meet in the middle on the three stories eating the industry alive.

In this episode we cover: 

  • Axios: one patient social engineer, a fake founder S...
Listen
Watch
Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Dateline NBC

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    The Joe Rogan Experience

    The official podcast of comedian Joe Rogan.

    The Clay Travis and Buck Sexton Show

    The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices