Hack.lu 2026

Eric Leblond

Éric Leblond is the co-founder and chief technology officer (CTO) of Stamus Networks and a member of the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities.
He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is emeritus member of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is also the lead developer of the Suricata Language Server, a real-time syntax checking and autocomplete app for Suricata rule writers.
Eric is a well-respected expert and speaker on network security.


Session

10-21
14:15
120min
HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata
Peter Manev, Eric Leblond

HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata

This workshop introduces HHAMMERR, a specialized threat hunting framework designed for modern detection engineering: Hypothesis, Hunt, Analyze, Modulate, Manage, Enhance, Refine, and Repeat. Built on the philosophy of "hunt manually once, automate forever," the session demonstrates how to move beyond traditional query-based methods into cost-effective, high-accuracy AI integration.

Using Suricata—the industry-standard open-source network analysis engine—as the primary data source, attendees will explore how to leverage its rich protocol, flow, and anomaly logs for deep network visibility. The workshop bridges the gap between traditional SIEM-based hunting and Agentic AI, focusing on building precise "AI Skills" rather than simply processing massive datasets.

Key Takeaways:

  • Methodology: Implementation of the HHAMMERR cycle to standardize hunting workflows.
  • Optimization: Techniques for building Agentic AI tools that prioritize data sovereignty, performance, and low token costs.
  • Practical Application: Hands-on malware hunt scenarios designed to provide immediate, actionable value for blue teams.

Moving past the hype of generative AI, this session provides a pragmatic roadmap for defenders to illuminate perimeter blind spots and automate complex detection tasks using the Claude AI plugin ecosystem and Suricata's network security data.

topic: hack.lu
Hollenfels