Skip to content
View Daniel-Andrawis's full-sized avatar
馃榾
Programming :)
馃榾
Programming :)

Block or report Daniel-Andrawis

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don鈥檛 include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user鈥檚 behavior. Learn more about reporting abuse.

Report abuse
Daniel-Andrawis/README.md

Daniel Andrawis

Detection engineer with a background in digital forensics and OSINT. I build and test detection content for AI and LLM abuse, mapped to MITRE ATLAS.

Everything I publish is defensive: detection, analysis, and public-source research.

MITRE ATLAS coverage matrix generated from the rules in detection-llm-misuse

Generated weekly from the rule files and the upstream ATLAS matrix, never hand-edited. tools/atlas_coverage.py

Current work

detection-llm-misuse - a detection pack for LLM inference-API abuse. Sigma and Google SecOps YARA-L rules mapped to MITRE ATLAS, with synthetic test fixtures and CI. Every rule ships with a dated experiment saying whether it still detects a live technique; one has already been demoted on the evidence.

ioc-enrich - multi-source IOC enrichment for analyst triage across VirusTotal, urlscan, and Censys, with provenance on every claim. Built so that "we did not look" is never mistaken for "we looked and found nothing".

Working with

Python 路 SQL 路 Bash 路 Sigma 路 YARA-L / Google SecOps 路 Elastic 路 Tines 路 MITRE ATT&CK 路 MITRE ATLAS

Elsewhere

Pinned Loading

  1. detection-llm-misuse detection-llm-misuse Public

    Provider-side detection content for LLM API abuse. Sigma + Google SecOps YARA-L, mapped to MITRE ATLAS, with synthetic test fixtures and CI.

    Python