detection
Safeguard articles tagged "detection" — guides, analysis, and best practices for software supply chain and application security.
16 articles
What Is Application Security Monitoring and How Do You Do It Well?
Application security monitoring is the continuous observation of an application's behavior to detect attacks, abuse, and security failures as they happen. Here is what to monitor and how to make signals actionable.
OWASP A09: Security Logging and Monitoring Failures — A Deep-Dive Guide
Security Logging and Monitoring Failures rank #9 in the OWASP Top 10 (2021). A deep dive into undetected breaches, dwell time, real incidents, and how to fix it.
False Positives vs False Negatives: What's the Difference?
A false positive flags something safe as dangerous. A false negative misses something dangerous entirely. One wastes your time; the other gets you breached.
Network Hacking Tools Attackers Use — and How Defenders Answer
A defender's field guide to the network hacking tools attackers reach for — reconnaissance, sniffing, exploitation, credential attacks — and the detection and control that answers each class.
Supply Chain Threat Detection: What to Watch For and How
A practical look at supply chain threat detection: the signals that reveal a compromised dependency, build system, or update channel, and how to catch them early.
Azure Sentinel for Supply Chain Detection
Sentinel has everything it needs to detect supply chain attacks in Azure — but only if the analytics rules are tuned to what those attacks actually look like.
PyPI Typosquatting Detection at Scale
Typosquatting remains a steady drumbeat on PyPI. What detection actually looks like when you're trying to catch it at ecosystem scale, and where the interesting edges are.
Supply Chain IoC Catalog
A practical catalog of indicators of compromise for software supply chain attacks, with detection queries and false-positive notes.
Datadog Security for Supply Chain Monitoring
Using Datadog's Cloud SIEM, ASM, and logs pipeline to monitor software supply chain threats across CI/CD, registries, and runtime.
Go Module Hijacking Detection
Module hijacking in Go is rare compared to npm, but it does happen, and the patterns worth watching are different from what you might expect from other ecosystems.
Incident Response Playbook for a Compromised Dependency
A concrete, timed playbook for the 72 hours after a critical dependency advisory — inventory, reachability, containment, remediation, and retrospective.
How One Engineer's Curiosity Saved Linux: The XZ Utils Backdoor Discovery Story
Andres Freund noticed SSH was 500ms slower than expected. That observation prevented the most dangerous supply chain attack in open source history from reaching stable Linux distributions.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.