Detection engineer with a background in digital forensics and OSINT. I build and test detection content for AI and LLM abuse, mapped to MITRE ATLAS.
Everything I publish is defensive: detection, analysis, and public-source research.
Generated weekly from the rule files and the upstream ATLAS matrix, never hand-edited. tools/atlas_coverage.py
detection-llm-misuse - a detection pack for LLM inference-API abuse. Sigma and Google SecOps YARA-L rules mapped to MITRE ATLAS, with synthetic test fixtures and CI. Every rule ships with a dated experiment saying whether it still detects a live technique; one has already been demoted on the evidence.
ioc-enrich - multi-source IOC enrichment for analyst triage across VirusTotal, urlscan, and Censys, with provenance on every claim. Built so that "we did not look" is never mistaken for "we looked and found nothing".
Python 路 SQL 路 Bash 路 Sigma 路 YARA-L / Google SecOps 路 Elastic 路 Tines 路
MITRE ATT&CK 路 MITRE ATLAS
- daniel-andrawis.github.io - writing


