$heversec

About

Hey there, My name is Noam Hever.
I like finding the activity that doesn’t belong - That malicious needle in the telemetry haystack.

What’s here#

  • Offensive techniques and their detections — how an attack actually works, what telemetry it leaves behind, and a detection you can deploy to your own siem/notebook environment.
  • Detection engineering research — building, tuning, benchmarking and validating detections that survive contact with production.
  • Security tooling — utilities I’ve built for hunting, triage, and detection work, with the
    reasoning behind them.
  • Project write-ups — whatever else I’m building or breaking.

A note on content#

Offensive material here exists so defenders can deeply understand the attacks and build detections against it.
covered alongside the telemetry and logic needed to catch them.

Elsewhere#

Links to my profiles are in the footer.


Views here are my own and do not represent my employer.