detection
Safeguard articles tagged "detection" — guides, analysis, and best practices for software supply chain and application security.
14 articles
An Alert Nobody Acts On Is Not a Control
Fifty fires a week and fifty dismissals is a habit, and the habit is dismissal. The fifty-first instance is real and arrives into a process trained on forty-nine that were not.
The Incident You Did Not Have Is the Cheapest Data You Will Get
A credential was public for nine minutes and nobody used it. No incident, no postmortem, nothing changed. Your incident history is a biased sample containing only the times luck ran out.
What Is Application Security Monitoring and How Do You Do It Well?
Application security monitoring is the continuous observation of an application's behavior to detect attacks, abuse, and security failures as they happen. Here is what to monitor and how to make signals actionable.
OWASP A09: Security Logging and Monitoring Failures — A Deep-Dive Guide
Security Logging and Monitoring Failures rank #9 in the OWASP Top 10 (2021). A deep dive into undetected breaches, dwell time, real incidents, and how to fix it.
False Positives vs False Negatives: What's the Difference?
A false positive flags something safe as dangerous. A false negative misses something dangerous entirely. One wastes your time; the other gets you breached.
Network Hacking Tools Attackers Use — and How Defenders Answer
A defender's field guide to the network hacking tools attackers reach for — reconnaissance, sniffing, exploitation, credential attacks — and the detection and control that answers each class.
Supply Chain Threat Detection: What to Watch For and How
A practical look at supply chain threat detection: the signals that reveal a compromised dependency, build system, or update channel, and how to catch them early.
Azure Sentinel for Supply Chain Detection
Sentinel has everything it needs to detect supply chain attacks in Azure — but only if the analytics rules are tuned to what those attacks actually look like.
Datadog Security for Supply Chain Monitoring
Using Datadog's Cloud SIEM, ASM, and logs pipeline to monitor software supply chain threats across CI/CD, registries, and runtime.
Incident Response Playbook for a Compromised Dependency
A concrete, timed playbook for the 72 hours after a critical dependency advisory — inventory, reachability, containment, remediation, and retrospective.
How One Engineer's Curiosity Saved Linux: The XZ Utils Backdoor Discovery Story
Andres Freund noticed SSH was 500ms slower than expected. That observation prevented the most dangerous supply chain attack in open source history from reaching stable Linux distributions.
GuardDuty Extended Threat Detection: What Defenders Actually Get
GuardDuty's extended threat detection correlates findings across signals into attack sequences. We dig into where it helps, where it misses, and how to wire it into supply chain incident response.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.