// solutions: detection engineering & AI security tooling

Ship detections like software.

Fixed-scope, project-based engagements with concrete deliverables. No slide decks. Working code you own.

brian@echotrail: ~
$ whoami
Brian Concannon, 15+ yrs building detection systems
@ FBI · CrowdStrike · Expel. Founder, EchoTrail.

BACKGROUND

// FBI Cyber// CrowdStrike// Expel// Raytheon

~/ start here: field reference

interactive · free

The Detection Engineering Lifecycle

An interactive map of detection engineering as an end-to-end lifecycle: eight stages, the defensive-approach decision, the feedback loops most diagrams skip, maturity guidance per stage, and where AI genuinely helps. Explore it by role, or take the PDF with you.

explore the lifecycle →

Read the manifesto on detection engineering in the age of AI, or the blog.

~/ services

~/ the data

api · mcp · dataset

EchoTrail Insights: Windows process behavior data

Every engagement is grounded in the same dataset we sell: over 300 million real process executions, growing every day, aggregated into prevalence, ancestry, paths, and hashes for tens of thousands of Windows executables. Free API key, MCP server, bulk dataset.

echotrail.io →

~/ git log --author=brian

7f3a9c2Founder@EchoTrail· 2018 – Present

Built EchoTrail Insights, the Windows process behavior dataset behind this site, and its API, MCP server, and free chat demo. Consulting on detection engineering with fixed-scope, project-based engagements.

c9a07f5Manager, Detection Tools Engineering@Expel· 2019 – 2020

Led the team building detection infrastructure for a 24/7 SOC, transforming raw telemetry from diverse security tools into actionable, high-fidelity detections. Joined during Series C, contributed through Series D.

2d6b1aaSenior Manager, Analytics Insight Team@CrowdStrike· 2013 – 2016

Joined as employee ~70 before the Falcon platform launched. Built CrowdStrike's first behavioral detection engine. Co-founded and led what became the Overwatch threat hunting team. Built streaming analytics processing millions of events per second.

f0e4c33Special Agent@FBI· 2005 – 2013

Investigated nation-state cyber intrusions. Selected for the FBI Cyber Action Team (CAT) responding to the most complex cyber incidents in the country. Built automated analysis tools for large-scale network forensics.

a1c5e90Senior Software Engineer II@Raytheon· 1999 – 2005

Led real-time embedded software development in C++ for Navy satellite communications. Designed encryption subsystems for classified SATCOM.

Let's talk about your detection program.

Book a 30-minute intro call to walk through your environment and where you need coverage, or send a message. Fixed scope, fixed price, working code you own.

brian@echotrail:~$ ./book-intro-call