Contact Sales
Contact Sales

Rethinking Detection Engineering: A Practical, Threat-Informed Path Forward for Modern Security Teams

This content is provided free of charge through collaboration between SANS and its sponsor(s). If you prefer not to share your contact details with the sponsor(s), you have the option of waiting approximately 30 days after the original publication date. After 30 days, to download the content, you will be required to create a SANS account, but your information will not be shared with the sponsor(s).

Rethinking Detection Engineering: A Practical, Threat-Informed Path Forward for Modern Security Teams (PDF, 0.93MB)Published: 24 Feb, 2026
Created by:
Erik Van BuggenhoutStamatis Chatzimangou
Erik Van Buggenhout & Stamatis Chatzimangou

Thank You To Our Sponsor

The threat landscape is evolving faster than ever, with defenders facing an explosion of data, technologies, and attack surfaces. This rapid evolution demands that detection engineering become faster, more adaptive, and more efficient. Yet, despite the evolution of frameworks, practices, and tools, maintaining a detection library is still challenging for most teams.

Detection Engineering That Scales: Practical Strategies for Resilient, Maintainable Security Operations

Related Webcast

Join SANS Senior Instructor Erik Van Buggenhout, Splunk’s Director of Product Management Tim Nary, and NVISO Detection Engineering SME Stamatis Chatzimangou as they explore effective detection engineering.

Man presenting webcast to laptop screen

Meet Your Authors