About
I'm Steven Stone, a cyber threat intelligence analyst, threat hunter, and detection engineer, and a U.S. Marine Corps veteran.
My work covers intelligence production, hypothesis-driven hunting, and detection development, mostly in Splunk. RedSheep Security is where I publish my own research from open sources, along with the tools and field manuals I build.
Focus
- Threat intelligence
- Actor tracking, tactical and strategic reporting, intelligence requirements.
- Threat hunting
- Hypothesis-driven hunts mapped to MITRE ATT&CK, built on the PEAK framework.
- Detection engineering
- Sigma, YARA, and Suricata rules, and Splunk SPL detections and dashboards.
- DFIR
- Windows event log analysis, host and network forensics, incident triage.