RedSheep SecurityRedSheepSecurity

Steven Stone

Cyber threat intelligence analyst, threat hunter, and detection engineer. This site holds my intelligence reports, hunt guides, and detection rules, and the tools I build to produce them.

GCTIGCFAGCIHGNFAGCFECISSPCISM
194
Reports
59
Hunt guides
20
Weekly summaries
17
Actors covered

TrendPulse

Operational

The collection and production pipeline behind the reports on this site: source collection, scoring, drafting, and a verification gate that checks every indicator, CVE, and citation against the fetched source text before anything is published.

PythonFastAPISQLiteClaude API

CTI Threat Hunt Map

Live

An ATT&CK v19.1 hunt reference: 375 hunts and 225 LOLBins with copy-ready Splunk, Elastic, and Corelight queries, cross-linked to 212 threat actors. Runs entirely in the browser.

ATT&CKSplunk SPLKQLPython

Windows Event Log Field Manual

Live

Advanced Windows Event Log Analysis (AWELA): 77 sections covering triage playbooks, process and system baselines, attack detection, and event references for Security, System, PowerShell, and Sysmon logs. Every query in Splunk SPL.

WindowsSysmonSplunk SPL

Honeypot Sensor Network

Operational

A T-Pot deployment running 30+ honeypot services on cloud infrastructure since March 2026. It collects attack telemetry and payloads for analysis and future malware reports.

T-PotElasticLinux

Detections

All rules →
-
Sigma rules
-
YARA rules
  • Loading rules