Loading…

Saturday September 12, 2026 10:30am - 11:30am CDT
Most security teams have no shortage of logs, yet turning that data into reliable detections is a different problem entirely.

In reality, detection efforts often fall apart because of messy data, vague assumptions, and a haphazard approach to building and maintaining them. The outcome is all too familiar: overwhelmed analysts tuning out alerts, threats slipping through the cracks, and detections that look impressive in presentations but crumble under real-world pressure.


This presentation pulls back the curtain on how detection engineering actually works in the trenches. We'll start with raw telemetry data and walk through the process of translating attacker behavior into testable hypotheses, then converting those hypotheses into detection logic that gets refined through ongoing feedback.


I'll introduce a practical lifecycle for detection engineering, covering research, hypothesis development, creation, validation, deployment, and tuning. This structured approach ensures that detections aren't just built once and forgotten, but evolve alongside the threats they're designed to catch.


Finally, we'll bridge detection engineering with threat hunting and broader cyber operations. You'll walk away with a straightforward framework for building detections that are not just technically sound, but genuinely useful when it matters most.
Speakers
avatar for Kyle Barboza

Kyle Barboza

Senior Threat Informed Defense Engineer, Financial Services Company
Kyle is a detection engineer and cyber operations leader focused on turning raw telemetry into actionable defense. He specializes in threat detection, incident response, and building scalable detection programs using automation and detection-as-code principles.With experience leading... Read More →
Saturday September 12, 2026 10:30am - 11:30am CDT
Swissôtel Chicago 323 E Wacker Dr, Chicago, IL 60601, USA

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link