// solutions: detection engineering & AI security tooling
Ship detections like software.
Fixed-scope, project-based engagements with concrete deliverables. No slide decks. Working code you own.
@ FBI · CrowdStrike · Expel. Founder, EchoTrail.
BACKGROUND
~/ start here: field reference
interactive · freeThe Detection Engineering Lifecycle
An interactive map of detection engineering as an end-to-end lifecycle: eight stages, the defensive-approach decision, the feedback loops most diagrams skip, maturity guidance per stage, and where AI genuinely helps. Explore it by role, or take the PDF with you.
explore the lifecycle →Read the manifesto on detection engineering in the age of AI, or the blog.
~/ services
Detection Rule Library
30 to 50 rules grounded in real-world experience, with MITRE ATT&CK mapping and tuning guidance.
from $8Kci/cdDetection-as-Code Pipeline
Version control, automated validation on every PR, and deployment to your SIEM/EDR via API.
from $15KaiAI-Powered SOC Tooling
Triage assistants, RAG knowledge bases, and enrichment pipelines. Prototype first, then production.
from $5K~/ the data
api · mcp · datasetEchoTrail Insights: Windows process behavior data
Every engagement is grounded in the same dataset we sell: over 300 million real process executions, growing every day, aggregated into prevalence, ancestry, paths, and hashes for tens of thousands of Windows executables. Free API key, MCP server, bulk dataset.
echotrail.io →~/ git log --author=brian
Built EchoTrail Insights, the Windows process behavior dataset behind this site, and its API, MCP server, and free chat demo. Consulting on detection engineering with fixed-scope, project-based engagements.
Led the team building detection infrastructure for a 24/7 SOC, transforming raw telemetry from diverse security tools into actionable, high-fidelity detections. Joined during Series C, contributed through Series D.
Joined as employee ~70 before the Falcon platform launched. Built CrowdStrike's first behavioral detection engine. Co-founded and led what became the Overwatch threat hunting team. Built streaming analytics processing millions of events per second.
Investigated nation-state cyber intrusions. Selected for the FBI Cyber Action Team (CAT) responding to the most complex cyber incidents in the country. Built automated analysis tools for large-scale network forensics.
Led real-time embedded software development in C++ for Navy satellite communications. Designed encryption subsystems for classified SATCOM.
Let's talk about your detection program.
Book a 30-minute intro call to walk through your environment and where you need coverage, or send a message. Fixed scope, fixed price, working code you own.
brian@echotrail:~$ ./book-intro-call