<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Detection Desk: The Threat Hunter’s Notepad]]></title><description><![CDATA["Welcome to The Threat Hunter’s Notepad, the podcast where we move beyond basic antivirus alerts, known file hashes, and C2 domain blocklists. Inspired by the work of Detection Engineer and Threat Hunter Manish Rawat, we dive deep into adversary emulation analysis and real-world telemetry, like the MITRE ATT&CK APT29 dataset. Join us as we explore how to catch advanced adversaries during their staging phase by analyzing Sysmon EventID 7 (Image Loads) and translating that behavior into robust Sigma rules. We believe that detection engineering isn't about keeping rules a secret; our blue team community gets stronger when we share methodology, validate our work, and improve collectively. Subscribe to learn how to build detection logic that catches what traditional rules miss!"]]></description><link>https://manishrawat21.substack.com/s/the-threat-hunters-notepad</link><image><url>https://substackcdn.com/image/fetch/$s_!0N0j!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0685241-5989-45bf-a8dc-4dd09d4c87ff_1024x1024.png</url><title>Detection Desk: The Threat Hunter’s Notepad</title><link>https://manishrawat21.substack.com/s/the-threat-hunters-notepad</link></image><generator>Substack</generator><lastBuildDate>Mon, 17 Aug 2026 22:58:00 GMT</lastBuildDate><atom:link href="https://manishrawat21.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Manish]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[manishrawat21@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[manishrawat21@substack.com]]></itunes:email><itunes:name><![CDATA[Manish Rawat]]></itunes:name></itunes:owner><itunes:author><![CDATA[Manish Rawat]]></itunes:author><googleplay:owner><![CDATA[manishrawat21@substack.com]]></googleplay:owner><googleplay:email><![CDATA[manishrawat21@substack.com]]></googleplay:email><googleplay:author><![CDATA[Manish Rawat]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Building a Phishing Detection Automation: From Unfinished Business to 45-Second Analysis]]></title><description><![CDATA[Sometimes things don&#8217;t go according to your plan. But sometimes, it just checks whether you have the potential or not.]]></description><link>https://manishrawat21.substack.com/p/building-a-phishing-detection-automation</link><guid isPermaLink="false">https://manishrawat21.substack.com/p/building-a-phishing-detection-automation</guid><dc:creator><![CDATA[Manish Rawat]]></dc:creator><pubDate>Wed, 12 Aug 2026 08:42:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!42-K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://manishrawat21.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://manishrawat21.substack.com/subscribe?"><span>Subscribe now</span></a></p><h3>The Problem That Wouldn&#8217;t Let Me Sleep</h3><p>If you&#8217;re a regular reader of my articles, you know I&#8217;ve had one unfinished business on my plate for a while now: &#8220;Creating AI Phishing Detection Automation.&#8221;</p><p>To be honest, I almost forgot about it.</p><p>Until I heard about it.</p><p><strong>Bank of Baroda. 1TB of customer data leaked.</strong> Reason? A single employee opened a phishing email.</p><p>I wasn&#8217;t shocked. Not even surprised.</p><p>The incident happened because India doesn&#8217;t treat security as an asset, it treats it as a liability. It&#8217;s a checkbox on a compliance form, not a core business function. You see organizations spending millions on flashy tools but not on the fundamentals: training, automation, and detection.</p><p>1TB of user data is gone. Who takes responsibility? What&#8217;s the next step? What security measures will they implement to prevent this from happening again? These are questions I don&#8217;t have answers to, and I suspect neither do they.</p><p>But here&#8217;s the thing: <strong>I&#8217;m not here to discuss what went wrong at Bank of Baroda.</strong> I&#8217;m here to discuss the solution.</p><div><hr></div><h3>The Real Talk</h3><p>Yes, catching phishing attacks is complicated. The attack surface is massive. The number of techniques is endless. But here&#8217;s what I realized: <strong>you don&#8217;t need perfect security; you need practical security.</strong></p><p>You don&#8217;t need to catch 100% of phishing attacks on day one. You need to catch the ones that matter. And you need to do it automatically, so your team doesn&#8217;t burn out reviewing emails.</p><p>So I asked myself a question that changed everything:</p><p><strong>&#8220;What if I could get a detailed, automated report of every email from a new sender?&#8221;</strong></p><p>Not manually analyzing each email. Not spending 20 minutes per message. But getting a comprehensive threat assessment in under a minute.</p><p>That&#8217;s when I decided to actually finish this unfinished business.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AUrs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AUrs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 424w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 848w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 1272w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AUrs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png" width="1358" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AUrs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 424w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 848w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 1272w, https://substackcdn.com/image/fetch/$s_!AUrs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8771343d-7738-49fc-8761-1c70c6c74d90_1358x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>The Idea (Before I Built It)</h3><p>Here&#8217;s what I wanted to build:</p><p><strong>A Phishing Detection Automation that:</strong></p><ul><li><p>Analyzes sender details (Is this sender real?)</p></li><li><p>Checks SPF/DKIM/DMARC (Is the email actually from them?)</p></li><li><p>Analyzes mail content (Is there phishing intent?)</p></li><li><p>Analyzes URLs (Are the links malicious?)</p></li><li><p>Generates a detailed report (What&#8217;s the verdict?)</p></li><li><p>Logs everything (For tracking and analysis)</p></li></ul><p>Simple concept. But the execution? That&#8217;s where things get interesting.</p><div><hr></div><h3>The Reality Check</h3><p>When I opened my SOC lab and started building, I realized something quickly: <strong>there&#8217;s no one-size-fits-all solution.</strong></p><p>You can&#8217;t just rely on one threat intelligence database. You can&#8217;t just run the email through an AI and call it done. You need multiple, independent verification mechanisms working in parallel.</p><p>Think of it like airport security. They don&#8217;t just check your ID. They check your luggage. They run it through X-ray. They might do a pat-down. Multiple independent checks catch things that any single check would miss.</p><p>That&#8217;s when I came up with the concept: <strong>&#8220;3 Lane Detection Workflow.&#8221;</strong></p><p>Three parallel lanes, each checking different threat vectors, all running at the same time.</p><div><hr></div><h3>The Solution: 3 Lane Detection Workflow</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!42-K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!42-K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 424w, https://substackcdn.com/image/fetch/$s_!42-K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 848w, https://substackcdn.com/image/fetch/$s_!42-K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 1272w, https://substackcdn.com/image/fetch/$s_!42-K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!42-K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png" width="906" height="604" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:604,&quot;width&quot;:906,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!42-K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 424w, https://substackcdn.com/image/fetch/$s_!42-K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 848w, https://substackcdn.com/image/fetch/$s_!42-K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 1272w, https://substackcdn.com/image/fetch/$s_!42-K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e4a914-6624-474d-a3cf-fd0fa610a07a_906x604.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AI Generated</figcaption></figure></div><h3>Lane 1: The Sender Verification Lane</h3><p>This lane answers a simple question: <strong>Is this sender real?</strong></p><p>I built it to:</p><ul><li><p>Extract email headers (Who is really sending this?)</p></li><li><p>Validate SPF/DKIM/DMARC (Is the sender authenticated?)</p></li><li><p>Check domain registration (Was this domain just created?)</p></li><li><p>Verify sender IP reputation (Is this IP known for phishing?)</p></li><li><p>Detect homograph attacks (Is this domain a typo version of a real company?)</p></li></ul><p>Why three checks? Because attackers are smart. They might spoof one thing but not another. If they fail multiple checks, it&#8217;s definitely phishing.</p><h3>Lane 2: The AI Content Analysis Lane</h3><p>This lane answers: <strong>What&#8217;s the intent of this email?</strong></p><p>I use Gemini AI to analyze:</p><ul><li><p>Language patterns (Is there urgency? Threats? Authority?)</p></li><li><p>Social engineering tactics (Is it trying to manipulate the user?)</p></li><li><p>Suspicious requests (Asking for password? Money? Data?)</p></li><li><p>Overall tone and quality</p></li></ul><p>AI is good at this because it understands context. A rule-based system would miss the subtle manipulation. An AI model understands that &#8220;urgent action required&#8221; + &#8220;verify your password&#8221; = credential harvesting attack.</p><h3>Lane 3: The URL Analysis Lane</h3><p>This lane answers: <strong>Are the links in this email malicious?</strong></p><p>I check URLs against:</p><ul><li><p>VirusTotal (90+ security vendors)</p></li><li><p>URLhaus (specialized phishing database)</p></li><li><p>URLscan (behavioral sandboxing)</p></li></ul><p>Three independent databases. If any one flags it, the URL is dangerous.</p><div><hr></div><h3>Building It: The Real Work Begins</h3><p>Here&#8217;s where it gets real. Having an idea is easy. Building it is different.</p><h3>Step 1: Setting Up the Framework</h3><p>I used n8n for orchestration (open source, self-hosted, free). No vendor lock-in. Full control.</p><p>I created the three lanes to run in parallel. This was important because sequential processing would take minutes. Parallel execution meant I could analyze an email in 45 seconds instead of several minutes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GHqV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GHqV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 424w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 848w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 1272w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GHqV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png" width="1358" height="509" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:509,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GHqV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 424w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 848w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 1272w, https://substackcdn.com/image/fetch/$s_!GHqV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862ffd0a-0171-4366-9b82-c183598a9878_1358x509.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Automation workflow</figcaption></figure></div><h3>Step 2: Integrating the APIs</h3><p>This is where I learned something important: <strong>Free tiers are powerful.</strong></p><ul><li><p>Gmail API: Free</p></li><li><p>VirusTotal: Free (500 requests/day)</p></li><li><p>URLhaus: Free</p></li><li><p>URLscan: Free</p></li><li><p>Gemini API: Affordable ($5&#8211;15/month for light usage)</p></li><li><p>Google Sheets: Free</p></li></ul><p>Total cost? $15/month. Not $1,200/month for a commercial SIEM. Not $500/month for a specialized phishing tool.</p><p>But wait. Free tier means rate limits. And rate limits mean I had to be smart about how I designed the workflow. I couldn&#8217;t just fire off every check simultaneously without hitting limits.</p><p>I learned to batch requests, queue them intelligently, and handle failures gracefully.</p><h3>Step 3: AI Prompting (The Trickiest Part)</h3><p>Getting Gemini to analyze phishing emails the way I wanted? This took more iterations than I expected.</p><p>First prompt: Generic. &#8220;Is this email phishing?&#8221; Got basic answers.</p><p>Second prompt: More detailed. &#8220;Analyze this email for phishing indicators.&#8221; Better, but still missing context.</p><p>Final prompt: Specific.</p><blockquote><p>&#8220;You are a senior SOC analyst and certified phishing forensics expert with 15+ years<br>investigating social engineering attacks. You have analyzed thousands of confirmed<br>phishing campaigns, BEC attacks, and credential-harvesting emails. You are known for<br>being precise, evidence-based, and for never overstating confidence when evidence is thin.</p><p>Your task: perform a deep social-engineering and manipulation-technique analysis of the<br>email text below. Do not just pattern-match on keywords&#8202;&#8212;&#8202;reason about intent, context,<br>and how a human target would actually experience this message.</p><p>ANALYSIS METHODOLOGY</p><p>Step 1&#8202;&#8212;&#8202;Read the full text({{ $json.text }}) once for overall tone, intent, and what action (if any) it&#8217;s<br>pushing the reader toward.</p><p>Step 2&#8202;&#8212;&#8202;For each of the following technique categories, determine if it is genuinely<br>present. A technique is only &#8220;detected&#8221; if there is direct textual evidence&#8202;&#8212;&#8202;do not<br>infer techniques that aren&#8217;t actually expressed in the words used.</p><p>TECHNIQUE TAXONOMY:<br>- urgency (artificial time pressure, &#8220;act now&#8221;, &#8220;immediately&#8221;, &#8220;asap&#8221;)<br>- fear (threats of loss, punishment, negative consequences)<br>- authority_impersonation (posing as IT, security team, government, executive)<br>- ceo_fraud (impersonating a senior executive requesting urgent action)<br>- financial_pressure (invoice, payment, wire transfer, refund themes)<br>- curiosity (vague enticing hooks&#8202;&#8212;&#8202;&#8220;you won&#8217;t believe&#8221;, unnamed attachments)<br>- scarcity (limited time/limited offer framing)<br>- reward (prizes, gifts, unexpected money)<br>- invoice_payment (fake billing, overdue payment notices)<br>- account_verification (fake &#8220;verify your account&#8221; prompts)<br>- password_reset (fake password/security alerts)<br>- mfa_fatigue (repeated authentication prompts, &#8220;approve this login&#8221;)<br>- shipping_notification (fake delivery/tracking themes)<br>- hr_impersonation (posing as HR, payroll, benefits)<br>- it_impersonation (posing as IT support, helpdesk)<br>- vendor_impersonation (posing as a known supplier/partner)<br>- legal_threat (fake legal action, lawsuit, compliance threats)<br>- tax_scam (fake tax authority communication)<br>- charity_scam (fake donation requests)<br>- brand_impersonation (mimicking a known company&#8217;s tone/branding)<br>- generic_greeting (absence of personalization&#8202;&#8212;&#8202;&#8220;Dear Customer&#8221; instead of a name)<br>- grammar_anomaly (unnatural phrasing, awkward translation, inconsistent tone)<br>- request_for_action (asks the reader to click, open, download, reply, or transfer something)&#8221;</p></blockquote><p>Then I had Gemini output structured JSON with:</p><ul><li><p>Verdict (PHISHING/LEGITIMATE/SUSPICIOUS)</p></li><li><p>Threat type (Credential harvesting, BEC, Malware, etc.)</p></li><li><p>Confidence score</p></li><li><p>Reasoning</p></li></ul><p>The key was: <strong>be specific about what you want, and structure the output for programmatic use.</strong></p><h3>Step 4: Testing and Refinement</h3><p>I tested it with one of my spoofed mail w</p><h3>Step 5: Google Sheets Integration</h3><p>I added automatic logging to Google Sheets. Every analyzed email gets a row with:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bVIv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bVIv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 424w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 848w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 1272w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bVIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png" width="1358" height="212" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:212,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bVIv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 424w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 848w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 1272w, https://substackcdn.com/image/fetch/$s_!bVIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69438886-e5b8-40f6-ae8f-6565d7823c47_1358x212.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><ul><li><p>Sender information</p></li><li><p>Authentication results</p></li><li><p>AI verdict</p></li><li><p>URL analysis results</p></li><li><p>Final classification</p></li><li><p>Timestamp</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QjZN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QjZN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 424w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 848w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 1272w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QjZN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png" width="1358" height="187" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:187,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QjZN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 424w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 848w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 1272w, https://substackcdn.com/image/fetch/$s_!QjZN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F994d3e81-52bb-40b7-a3c8-a3c9206040bb_1358x187.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This wasn&#8217;t just for logging. It&#8217;s for pattern recognition. Over time, I can see trends. Who are the repeat attackers? What patterns do we see? When are we getting hit hardest?</p><p><strong>Thanks for reading.</strong></p><p>This was unfinished business. Now it&#8217;s done.</p><p>What&#8217;s your unfinished business?</p><div><hr></div><h3>What I&#8217;d Tell You If You&#8217;re Building Something Similar</h3><ol><li><p><strong>Start with the problem, not the solution.</strong> I started with &#8220;How do I detect phishing?&#8221; not &#8220;Which database should I use?&#8221;</p></li><li><p><strong>Use existing tools.</strong> n8n is powerful. Free APIs are powerful. Don&#8217;t reinvent the wheel.</p></li><li><p><strong>Test with real data.</strong> My workflow works on the phishing emails I actually receive, not hypothetical ones.</p></li><li><p><strong>Multiple independent checks.</strong> One database catches what another misses. Defense-in-depth is real.</p></li><li><p><strong>Measure everything.</strong> I log every step. I can see where bottlenecks are. I can see what&#8217;s working.</p></li><li><p><strong>Ship it.</strong> Don&#8217;t wait for perfect. Get something working, then improve it.</p></li></ol><div><hr></div><h3>Where This Goes Next</h3><p>Right now, this workflow analyzes text-based emails. Next, I&#8217;m adding:</p><p><strong>Phase 2: Attachment Analysis</strong></p><ul><li><p>File hash verification</p></li><li><p>Sandbox submission</p></li><li><p>Malware signature detection</p></li></ul><p><strong>Phase 3: SIEM Integration</strong></p><ul><li><p>Splunk integration</p></li><li><p>Real-time alerting</p></li><li><p>Incident correlation</p></li></ul><p><strong>Phase 4: Machine Learning</strong></p><ul><li><p>Historical pattern analysis</p></li><li><p>Threat actor identification</p></li><li><p>Predictive scoring</p></li></ul><p>But for now? This works. And it solves the problem I set out to solve: detecting phishing attacks automatically, accurately, and quickly.</p><div><hr></div><h3>Final Thoughts</h3><p>When I heard about the Bank of Baroda incident, I felt two things:</p><p>First, frustration. Because it was preventable. A simple email filtering system would have caught that phishing email.</p><p>Second, motivation. Because I realized: <strong>security doesn&#8217;t have to be expensive or complex. It has to be practical.</strong></p><p>You don&#8217;t need a million-dollar SIEM to catch phishing. You need automation. You need to combine multiple detection methods. You need to log everything.</p><p>And you need to actually do it. Not plan it. Not talk about it. Do it.</p><p>That&#8217;s what this workflow does.</p><div><hr></div><h3>If You Want to Build This</h3><p>The workflow is open source on <a href="https://github.com/manishrawat21/Phishing-Triage-Automation/">GitHub</a>.</p><ul><li><p>JSON file.</p></li><li><p>n8n.</p></li><li><p>All free tools.</p></li><li><p>Step-by-step setup guide.</p></li></ul><p>You can deploy this in your own environment in 30 minutes.</p><p>Because security shouldn&#8217;t be something only enterprises can afford. It should be something everyone can implement.</p><p>If you build it, if you improve it, if you have feedback&#8202;&#8212;&#8202;reach out. The goal is to make phishing detection accessible to everyone.</p><div><hr></div><h3>Connect</h3><p>If you&#8217;re interested in detection engineering, threat hunting, or security automation, let&#8217;s connect:</p><p><strong>LinkedIn</strong>: linkedin.com/in/manishrawat21</p><p><strong>GitHub</strong>: github.com/manishrawat21</p><p><strong>Email</strong>: <a href="mailto:rawatmanish21@outlook.com">rawatmanish21@outlook.com</a></p><p>Or if you have questions about this workflow, I&#8217;m here.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://manishrawat21.substack.com/p/building-a-phishing-detection-automation?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://manishrawat21.substack.com/p/building-a-phishing-detection-automation?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Zero-Touch Security: The 45-Second Automated Phishing Triage Pipeline]]></title><description><![CDATA[Moving Threat Triage Upstream to Prevent Enterprise Data Exfiltration]]></description><link>https://manishrawat21.substack.com/p/zero-touch-security-the-45-second</link><guid isPermaLink="false">https://manishrawat21.substack.com/p/zero-touch-security-the-45-second</guid><dc:creator><![CDATA[Manish Rawat]]></dc:creator><pubDate>Thu, 06 Aug 2026 05:11:11 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/210027122/14c6f95d7dcb36016b7b2a761a96357c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Most enterprises are highly vulnerable to phishing attacks, often standing just a single compromised corporate inbox away from a massive data breach. This exact security gap became a reality during the cyber incident at the Bank of Baroda in late July 2026. A threat actor was able to compromise an employee email account, and because that user identity possessed access to shared directories, the attacker was able to quietly compile, zip, and exfiltrate approximately one terabyte of highly sensitive corporate and customer files. This stolen data included customer onboarding forms, Aadhaar and PAN card copies, savings and current account records, and internal audits from over one thousand branches across India.</p><p>To address this critical front-line vulnerability, security engineer Manish Rawat designed the Automated Phishing Triage Pipeline. Instead of waiting for an employee to make a mistake and click a malicious link, this pipeline moves threat triage entirely upstream. It intercepts and processes incoming email telemetry in real time, before the message ever reaches a user&#8217;s active session.</p><p>The architecture processes emails across three parallel analytical lanes:</p><ul><li><p><strong>Lane 1 (Envelope Verification):</strong> Parses SPF/DKIM/DMARC alignments, conducts WHOIS domain age checks, queries AbuseIPDB server reputation, and scans for homoglyphs attempting to spoof known vendors.</p></li><li><p><strong>Lane 2 (Link &amp; Intent Analysis):</strong> Extracts body text, uses an LLM to evaluate psychological social engineering tactics, computes URL entropy, and automates sandbox scans via urlscan.io.</p></li><li><p><strong>Lane 3 (Payload Detonation):</strong> Decodes attachments, computes SHA-256 hashes, queries VirusTotal, detonations unknown payloads inside a secure Hybrid Analysis sandbox, and uses an LLM to summarize execution logs.</p></li></ul><p>By merging sender, link, and payload telemetry into a single investigation record, the system triggers an automated session lockout the moment a threat threshold is crossed completely closing the exfiltration window before a single file leaves the network. In practice, this automation compresses traditional SOC analyst investigative timelines from 30 to 45 minutes down to just 45 seconds of total execution, driving a 98% reduction in manual investigative overhead and a 100% reduction in manual initial triage time</p>]]></content:encoded></item><item><title><![CDATA[CISA KEV Threat Intel Orchestrator: Community Milestones and Project Growth]]></title><description><![CDATA[When I built the CISA KEV Threat Intel Orchestrator, my primary goal was to solve a very specific, practical problem in security operations]]></description><link>https://manishrawat21.substack.com/p/cisa-kev-threat-intel-orchestrator</link><guid isPermaLink="false">https://manishrawat21.substack.com/p/cisa-kev-threat-intel-orchestrator</guid><dc:creator><![CDATA[Manish Rawat]]></dc:creator><pubDate>Tue, 04 Aug 2026 04:08:12 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/209732684/8d83a0b3a75d283c6e59d8d49f7ee606.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Translating a newly weaponized vulnerability from the CISA KEV catalog into a production-ready Sigma detection rule traditionally costs an analyst four to six hours of manual research and writing. This automated pipeline was designed to handle that entire process in real time, reducing manual engineering effort to zero minutes per CVE.</p><p>Since launching the project, the organic response from the cybersecurity community has provided some incredible, objective validation that this is a challenge many security teams face.</p><p>Instead of another project update, I wanted to share a few of the milestones this repository has reached purely through organic discovery:</p><ul><li><p><strong>Newsletter Features:</strong> The pipeline was featured in the Blue Team section of <strong>TLDRSec</strong>, one of the industry&#8217;s largest security newsletters. It was also highlighted in <strong>Detection Engineering Weekly</strong>, focusing specifically on the automated Sigma generation, suppression logic, and MITRE ATT&amp;CK mapping.</p></li><li><p><strong>Community Sharing:</strong> Security researcher Nicolas Krassas shared the repository on X, bringing the project to the attention of over 7,500 security professionals.</p></li><li><p><strong>Organic Reach:</strong> The repository has driven nearly 1,000 monthly views to my associated technical publications on Medium and Substack. It continues to see regular organic cloning and bookmarking from practitioners.</p></li><li><p><strong>Project Interest:</strong> The repository has officially passed <strong>36 GitHub stars</strong>.</p></li></ul><p>This recognition has been incredibly encouraging, especially since the project began as a personal portfolio piece to showcase practical automation in threat intelligence, SOC operations, and AI-assisted security workflows.</p><p>The pipeline is still actively developing. The current technical roadmap includes auto-deploying generated rules directly to SIEM platforms and establishing automated testing for rules against sample logs before they reach an analyst&#8217;s inbox.</p><p>If you are a defender looking to streamline your detection engineering workflows, the repository is fully open source and public. I am also actively open to professional roles and opportunities in Detection Engineering, Threat Intelligence, and Security Automation, and would love to connect with teams working in this space.</p><p>&#128279; GitHub Repository: <a href="https://github.com/manishrawat21/Cisa-KEV-Threat-Intel-Orchestrator">https://github.com/manishrawat21/Cisa-KEV-Threat-Intel-Orchestrator</a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://manishrawat21.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://manishrawat21.substack.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Episode 2: The PowerShell Detection Gap (And How We Fix It)]]></title><description><![CDATA[49% of modern cyberattacks use PowerShell, yet attackers hide for almost a year. Here is how we used 196,000 Sysmon events to build a Sigma rule that actually catches fileless malware.]]></description><link>https://manishrawat21.substack.com/p/episode-2-the-powershell-detection</link><guid isPermaLink="false">https://manishrawat21.substack.com/p/episode-2-the-powershell-detection</guid><dc:creator><![CDATA[Manish Rawat]]></dc:creator><pubDate>Sat, 18 Jul 2026 05:50:31 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207519896/2377e8bdefde7e7a713b3b628973ccd9.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Welcome to Episode 2 of <strong>The Threat Hunter&#8217;s Notepad</strong>!</p><p>In today&#8217;s episode, we are tackling a massive blind spot that is costing organizations millions. In December 2025, threat actors like Storm-0249 escalated their ransomware operations using fileless PowerShell execution. They used legitimate Windows utilities to fetch and run scripts without ever touching the disk, leaving security teams completely unaware until the damage was already done.</p><p>The data behind this threat is staggering. Currently, 49% of cyberattacks use PowerShell somewhere in the attack chain, and 77% of successful attacks involve fileless malware. Because PowerShell is a legitimate, Microsoft-signed tool used daily by system administrators, traditional antivirus cannot just block it. Security products usually try to whitelist it entirely or alert on every single execution, which creates so much noise that SOC teams just tune it out. The result is that attackers can operate undetected inside networks for an average of 292 days&#8212;almost a full year.</p><p><strong>What You&#8217;ll Hear in This Episode:</strong></p><ul><li><p><strong>The APT29 Telemetry Analysis:</strong> We break down Detection Engineer Manish Rawat&#8217;s analysis of 196,071 Sysmon events from the MITRE ATT&amp;CK APT29 dataset to see how advanced adversaries actually operate.</p></li><li><p><strong>The Four Malicious Patterns:</strong> We explain why you need to stop relying on simple string matching and start hunting for behavioral combinations. We cover how attackers use encoding (like Base64 and <code>-enc</code> flags), leverage Office apps like Excel and Word to spawn PowerShell, rely on standard evasion flags (<code>-NoProfile</code>, <code>-window hidden</code>, <code>-ep bypass</code>), and make network connections with built-in cmdlets like <code>Invoke-WebRequest</code>.</p></li><li><p><strong>Building a Rule That Actually Works:</strong> We discuss the custom Sigma rule designed to catch these specific malicious combinations by correlating parent processes with network activity and evasion flags.</p></li><li><p><strong>Cutting the Noise:</strong> We explore how looking for suspicious process chains (like <code>cmd.exe</code> spawning <code>control.exe</code>, which then spawns PowerShell) can reduce the noise from 10,000 generic alerts down to just 5 to 10 high-confidence, actionable alerts per day.</p></li></ul><p>PowerShell abuse is not going away, and the next attack is likely already running in someone&#8217;s environment right now. Hit play on the audio above to learn how to catch fileless attacks at the initial staging phase, before the adversary establishes persistence.</p><p><strong>Resources Mentioned:</strong></p><ul><li><p><strong>GitHub Release:</strong> The complete, production-ready Sigma rule, along with the Splunk SPL conversion, is available on Manish Rawat&#8217;s GitHub repository.</p></li><li><p><strong>MITRE ATT&amp;CK Mappings:</strong> This rule provides coverage across the attack lifecycle, mapping directly to techniques T1059.001 (PowerShell), T1027 (Obfuscation), and T1566.001 (Spearphishing Attachment).</p></li><li><p><strong>Connect:</strong> You can follow Manish Rawat&#8217;s ongoing threat hunting research on LinkedIn.</p></li></ul><p><em>(Grab your notepad, tune in, and let&#8217;s start hunting. The blue team gets stronger when we share our work!)</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://manishrawat21.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://manishrawat21.substack.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Episode 1: Catching APT29 Staging (Why EventID 1 Isn't Enough)]]></title><description><![CDATA[Most SOC teams only watch process creation. Today, we're tracking what processes load to catch advanced adversaries before they execute.]]></description><link>https://manishrawat21.substack.com/p/episode-1-catching-apt29-staging</link><guid isPermaLink="false">https://manishrawat21.substack.com/p/episode-1-catching-apt29-staging</guid><dc:creator><![CDATA[Manish Rawat]]></dc:creator><pubDate>Wed, 15 Jul 2026 08:26:54 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207127511/b5716a485bcd71225bc9054f9aff40f8.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Welcome to the first official episode of <strong>The Threat Hunter&#8217;s Notepad</strong>!</p><p>In today&#8217;s recording, we are injecting some serious energy into detection engineering as we tackle a massive blind spot in most Security Operations Centers (SOCs). When analysts think about catching malware, they usually look for antivirus alerts, known file hashes, or C2 domain blocklists. But as we discuss in this episode, advanced adversaries like APT29 simply do not operate that way.</p><p>If you walk into a typical SOC and ask what Sysmon events they monitor, they will almost always say EventID 1 (Process Creation). But by the time a malicious payload actually executes, you are already too late.</p><p><strong>What You&#8217;ll Hear in This Episode:</strong></p><ul><li><p><strong>The MITRE ATT&amp;CK APT29 Deep Dive:</strong> We explore Detection Engineer Manish Rawat&#8217;s incredible analysis of 196,071 Sysmon events from a full adversary simulation.</p></li><li><p><strong>The Power of EventID 7 (Image Loads):</strong> We explain why the real secret to catching adversaries is looking at the <em>staging phase</em>. Discover how monitoring what a process loads (EventID 7) reveals malware hiding in temporary directories.</p></li><li><p><strong>Pattern Matching Over Hashes:</strong> Learn why traditional rules miss threats and how to hunt for behavioral patterns instead. We discuss why even signed, legitimate tools like <code>Rar.exe</code> or <code>python.exe</code> become highly suspicious when they start loading modules from <code>\Temp\</code> directories.</p></li><li><p><strong>The Notepad Philosophy:</strong> True detection engineering doesn&#8217;t start with polished dashboards&#8212;it starts with boolean logic mapped out on a physical notepad. We break down the raw, permissive logic needed to cast a wide net during threat hunting, and how to eventually tune out the noise.</p></li></ul><p><strong>The Blue Team Gets Stronger Together</strong> AI can generate a Sigma rule, but it cannot do the analysis, environmental tuning, or business context interpretation required to actually protect a network. That is your competitive advantage as a detection engineer. We believe in sharing our methodology and validating each other&#8217;s work, rather than gatekeeping detection logic.</p><p>Hit play on the audio above to dive into the excitement, tension, and curiosity of real-world threat hunting!</p><p><strong>Resources Mentioned:</strong></p><ul><li><p><strong>GitHub Release:</strong> The complete, production-ready Sigma rule discussed in this episode will be released soon on Manish Rawat&#8217;s <a href="https://github.com/manishrawat21">GitHub</a>.</p></li><li><p><strong>Connect:</strong> You can follow Manish Rawat&#8217;s threat hunting research on <a href="https://www.linkedin.com/in/manishrawat21/">LinkedIn.</a><br><br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://manishrawat21.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://manishrawat21.substack.com/subscribe?"><span>Subscribe now</span></a></p></li></ul>]]></content:encoded></item></channel></rss>