Remi Seguy
With over 25+ years in the cybersecurity field, I have dedicated my career to safeguarding organisations by developing robust SOC and effective incident response teams. As a passionate advocate for knowledge sharing and collaboration - "sharing is caring"- I have actively contributed to the cybersecurity community and related open-source projects, such as MISP. In my current role, I have led the OpenTide initiative, turning it into a project at the core of the Detection Engineering team. I am looking for exchanging and collaborating with other Detection Engineering teams to develop repeatable, traceable, and pragmatic processes, effectively bridging the gap between Threat Intelligence, Threat Hunting, and Threat Detection.
Session
Threat-informed detection engineering is often difficult to operationalise: security teams must transform cyber threat intelligence into actionable detections while managing tooling complexity, detection coverage, and operational workflows.
This hands-on workshop builds on the talk “OpenTIDE – Threat-Informed Detection Engineering Made Easy” and guides participants through deploying their own operational OpenTIDE platform using GitHub or GitLab. Participants will configure documentation pipelines, explore Detection-as-Code workflows, and learn how OpenTIDE JSON Schemas integrate with IDEs such as VS Code or Kiro to simplify YAML authoring through validation and auto-completion when describing threat vectors, defining detection objectives or implementing and deploying detection rule custom queries tuned from Sigma or any available sources.
The workshop also includes a demonstration of the full Managed Detection Rule lifecycle using a staging Splunk Enterprise Security environment.
Participants will leave with a working OpenTIDE deployment and the practical foundations required to start building threat-informed DetectionOps capabilities in their own organisations.