Shell → Signal
Purple-team research from a home detection lab. We detonate real attack techniques, capture every trace they leave behind, and turn that telemetry into detections.
$ ./detonate --technique T1059.001 --target ws01 [+] payload executed · marker logged $ search index=sysmon EventCode=1 host=ws01 [+] 1 process tree · 4 network events · 1 script block $ echo "first write-up landing soon"
🔴 The AttackWhat the technique does and how it was run, mapped to MITRE ATT&CK.
🔵 The SignalThe raw telemetry it leaves: Sysmon, Windows events, auditd, firewall, DNS.
🟣 The VerdictThe detection that catches it, what it missed, and how to tune it.