
Erwan CHEVALIER
Principal Threat Researcher
Articles by Erwan CHEVALIER

Leveraging Landlock telemetry for Linux detection engineering
This blogpost explore how Landlock as an interesting security mechanism and a valuable source of telemetry for detection engineering.

Sekoia Strengthens Collective Cyber Defense at NATO CCDCOE’s Crossed Swords 2025 Exercise
Sekoia.io delivered its technology and expertise to the NATO CCDCOE’s Crossed Swords 2025 (XS25) exercise to gather critical insights and validate our defensive capabilities in a military-grade environment.

Detection engineering at scale: one step closer (part three)
Following our first article explaining our detection approach and associated challenges, the second one detailing the regular and automated actions implemented through our CI/CD pipelines, we will now conclude this series by presenting the continuous improvement loop that allows us to achieve our long-term objectives, incorporating the principles of detection engineering.

Detection engineering at scale: one step closer (part two)
In this article, we will build upon the previous discussion of our detection approach and associated challenges by detailing the regular and automated actions implemented through our CI/CD pipelines.

Double-Tap Campaign: A Russia-Nexus APT Linked to APT28 Targets Kazakhstan's Diplomatic Relations
Uncover the details of UAC-0063 cyberespionage campaign in Kazakhstan and its potential connection to APT28

Detection engineering at scale: one step closer (part one)
Security Operations Center (SOC) and Detection Engineering teams frequently encounter challenges in both creating and maintaining detection rules, along with their associated documentation, over time.

Emulating and Detecting Scattered Spider-like Attacks
Explore a use-case scenario demonstrating how to detect scattered spider attacks in AWS environments and enhance your cloud security.

When a botnet cries: Detecting botnet infection chains
Infection chains used by commodity malware are constantly evolving and use various tricks to bypass security measures and/or user awareness. BumbleBee, QNAPWorm, IcedID and Qakbot are all often used as first-stage malicious code.

XDR detection engineering at scale: Crafting detection rules for SecOps efficiency
In this blog post we present Sekoia’s process to create detection rules, which first requires explaining our detection workflow as well as understanding Sekoia XDR history and specificities.

Sekoia mid-2022 ransomware threat landscape
Sekoia presents its Ransomware threat landscape for the first semester of 2022, with the following key points...

Vice Society: A discreet but steady double extortion ransomware group
Vice Society is a little-known double extortion group that exfiltrates its victims' data and threatens its victims to leak their information.

An insider insight into Conti operations – Part Two
This is the second part of our blog post about Conti, here we'll see how to detect Conti Operations techniques and much more.

An insider insight into Conti operations - Part One
In part 1, we focus on the Conti ransomware group whose training material was recently leaked on a cybercrime forum.


