<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ryan Fetterman</title><link>https://fetterm4n.github.io/</link><description>Recent content on Ryan Fetterman</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 06 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://fetterm4n.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>GGUF-tools</title><link>https://fetterm4n.github.io/tools/gguf-tools/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/tools/gguf-tools/</guid><description>Utility scripts and tooling for GGUF model workflows and experimentation.</description></item><item><title>Infosec Jupyterthon - Threat Hunting in Three Dimensions</title><link>https://fetterm4n.github.io/tools/infosec-jupyterthon-threat-hunting-three-dimensions/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/tools/infosec-jupyterthon-threat-hunting-three-dimensions/</guid><description>Notebook-driven threat hunting resources from the Infosec Jupyterthon project.</description></item><item><title>LUCID (LLM-driven Understanding, Classification &amp; Insight for Detections)</title><link>https://fetterm4n.github.io/tools/lucid/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/tools/lucid/</guid><description>Detection rule classifier project for transforming rule logic into model-assisted reasoning workflows.</description></item><item><title>Macro-level ATT&amp;CK Trending</title><link>https://fetterm4n.github.io/tools/macro-level-attack-trending/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/tools/macro-level-attack-trending/</guid><description>Repository for macro-level ATT&amp;amp;CK trend analysis and supporting data workflows.</description></item><item><title>PEAK Threat Hunting</title><link>https://fetterm4n.github.io/tools/peak-threat-hunting/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/tools/peak-threat-hunting/</guid><description>Framework and resources for practical, model-assisted threat hunting.</description></item><item><title>Applied Interpretability: Foundation-Sec-Instruct Goes Under the Microscope</title><link>https://fetterm4n.github.io/research/publications/applied-interpretability-foundation-sec-instruct/</link><pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/applied-interpretability-foundation-sec-instruct/</guid><description>Exploring mechanistic interpretability methods for understanding internal behavior of security-focused language models.</description></item><item><title>LUCID (LLM-driven Understanding, Classification &amp; Insight for Detections)</title><link>https://fetterm4n.github.io/research/publications/lucid/</link><pubDate>Thu, 05 Feb 2026 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/lucid/</guid><description>A framework for transforming traditional detection engineering logic into LLM-driven reasoning systems.</description></item><item><title>Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends</title><link>https://fetterm4n.github.io/research/publications/splunk-predicting-cyber-fraud-through-real-world-events-insights-from-domain-registrati/</link><pubDate>Mon, 15 Dec 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-predicting-cyber-fraud-through-real-world-events-insights-from-domain-registrati/</guid><description>By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.</description></item><item><title>Toward Quantitative Modeling of Cybersecurity Risks due to AI Misuse</title><link>https://fetterm4n.github.io/research/publications/quantitative-modeling-ai-misuse/</link><pubDate>Sun, 14 Dec 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/quantitative-modeling-ai-misuse/</guid><description>A framework for estimating cyber risk introduced by malicious and unintended AI use patterns.</description></item><item><title>CERT-EU: Defending at Machine Speed</title><link>https://fetterm4n.github.io/research/talks/cert-eu-defending-at-machine-speed/</link><pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/cert-eu-defending-at-machine-speed/</guid><description>Presentation materials for Defending at Machine Speed, focused on practical use of security context to improve AI-assisted detection and response workflows.</description></item><item><title>The TTP Ep15: The Threat Hunter's Cookbook</title><link>https://fetterm4n.github.io/research/talks/the-ttp-ep15-threat-hunters-cookbook/</link><pubDate>Tue, 23 Sep 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/the-ttp-ep15-threat-hunters-cookbook/</guid><description>YouTube appearance focused on methods and use cases from The Threat Hunter&amp;rsquo;s Cookbook.</description></item><item><title>AI attackers on adoption curve with first report of a novel malware strain</title><link>https://fetterm4n.github.io/research/talks/ai-attackers-adoption-curve/</link><pubDate>Tue, 09 Sep 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/ai-attackers-adoption-curve/</guid><description>Video appearance covering AI-enabled adversary trends and emerging malware behavior.</description></item><item><title>Introducing… The Threat Hunter’s Cookbook!</title><link>https://fetterm4n.github.io/research/publications/splunk-introducing-the-threat-hunter-s-cookbook/</link><pubDate>Wed, 06 Aug 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-introducing-the-threat-hunter-s-cookbook/</guid><description>The security experts on the SURGe team have released The Threat Hunter’s Cookbook, a hands-on guide for security practitioners that features actionable insights into threat hunting methods, ready-to-use queries, and more.</description></item><item><title>The Threat Hunter's Cookbook</title><link>https://fetterm4n.github.io/research/publications/threat-hunters-cookbook/</link><pubDate>Wed, 06 Aug 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/threat-hunters-cookbook/</guid><description>Hands-on guide for modern threat hunting workflows with practical methods and queries.</description></item><item><title>Defending at Machine Speed: Guiding LLMs with Security Context</title><link>https://fetterm4n.github.io/research/publications/splunk-defending-at-machine-speed-guiding-llms-with-security-context/</link><pubDate>Tue, 24 Jun 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-defending-at-machine-speed-guiding-llms-with-security-context/</guid><description>Enhance LLM performance for cybersecurity tasks with few-shot learning, RAG, &amp;amp; fine-tuning guide models for accurate PowerShell classification.</description></item><item><title>Defending at Machine-Speed: Accelerated Threat Hunting with Open Weight LLM Models</title><link>https://fetterm4n.github.io/research/publications/splunk-defending-at-machine-speed-accelerated-threat-hunting-with-open-weight-llm-model/</link><pubDate>Wed, 02 Apr 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-defending-at-machine-speed-accelerated-threat-hunting-with-open-weight-llm-model/</guid><description>Splunker Ryan Fetterman explains how Splunk DSDL 5.2 enhances cybersecurity operations, streamlining PowerShell script classification and reducing analyst workload by 250x.</description></item><item><title>Autonomous Adversaries: Are Blue Teams Ready for Cyberattacks To Go Agentic?</title><link>https://fetterm4n.github.io/research/publications/splunk-autonomous-adversaries-are-blue-teams-ready-for-cyberattacks-to-go-agentic/</link><pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-autonomous-adversaries-are-blue-teams-ready-for-cyberattacks-to-go-agentic/</guid><description>Explore the impact of autonomous adversaries on cybersecurity as AI and LLMs evolve.</description></item><item><title>The TTP Episode 7: Explore this year's Macro-ATT&amp;CK findings</title><link>https://fetterm4n.github.io/research/talks/trp-episode-7-macro-attack/</link><pubDate>Thu, 05 Dec 2024 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/trp-episode-7-macro-attack/</guid><description>YouTube discussion of annual Macro-ATT&amp;amp;CK findings and defender takeaways.</description></item><item><title>Macro ATT&amp;CK for a TTP Snack</title><link>https://fetterm4n.github.io/research/publications/splunk-macro-att-and-ck-for-a-ttp-snack/</link><pubDate>Mon, 21 Oct 2024 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-macro-att-and-ck-for-a-ttp-snack/</guid><description>Splunk&amp;rsquo;s Mick Baccio and Ryan Fetterman explore 2024&amp;rsquo;s macro-level cyber incident trends through the lens of the MITRE ATT&amp;amp;CK framework.</description></item><item><title>Macro-ATT&amp;CK 2024: A Five-Year Perspective</title><link>https://fetterm4n.github.io/research/publications/splunk-macro-att-and-ck-2024-a-five-year-perspective/</link><pubDate>Thu, 10 Oct 2024 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-macro-att-and-ck-2024-a-five-year-perspective/</guid><description>Splunk’s Ryan Fetterman and Tamara Chacon dive into attacker techniques, trends, and blue team tips for analyzing and visualizing data from the past year.</description></item><item><title>Add To Chrome? - Part 4: Threat Hunting in 3-Dimensions: M-ATH in the Chrome Web Store</title><link>https://fetterm4n.github.io/research/publications/splunk-add-to-chrome-part-4-threat-hunting-in-3-dimensions-m-ath-in-the-chrome-web-stor/</link><pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-add-to-chrome-part-4-threat-hunting-in-3-dimensions-m-ath-in-the-chrome-web-stor/</guid><description>SURGe experiments with a method to find masquerading using M-ATH with Splunk and the DSDL App.</description></item><item><title>Infosec Jupyterthon 2024 Day 1</title><link>https://fetterm4n.github.io/research/talks/infosec-jupyterthon-2024-day1/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/infosec-jupyterthon-2024-day1/</guid><description>Live stream appearance at Infosec Jupyterthon 2024 Day 1.</description></item><item><title>Revisiting the Big Picture: Macro-level ATT&amp;CK Updates for 2023</title><link>https://fetterm4n.github.io/research/publications/splunk-revisiting-the-big-picture-macro-level-att-and-ck-updates-for-2023/</link><pubDate>Tue, 26 Sep 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-revisiting-the-big-picture-macro-level-att-and-ck-updates-for-2023/</guid><description>SURGe reviews the latest attacker trends and behaviors with this look at four years of ATT&amp;amp;CK data from some of the largest and most trusted threat reporting sources.</description></item><item><title>Threat Hunting for Dictionary-DGA with PEAK</title><link>https://fetterm4n.github.io/research/publications/splunk-threat-hunting-for-dictionary-dga-with-peak/</link><pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-threat-hunting-for-dictionary-dga-with-peak/</guid><description>Explore applied model-assisted threat hunting for dictionary-based domain generation algorithms using the SURGe Security Research Team&amp;rsquo;s PEAK Threat Hunting Framework.</description></item><item><title>Threat Informed Planning with Macro-level ATT&amp;CK Trending</title><link>https://fetterm4n.github.io/research/talks/threat-informed-planning-macro-attack/</link><pubDate>Wed, 07 Jun 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/talks/threat-informed-planning-macro-attack/</guid><description>YouTube appearance discussing threat-informed planning and macro-level ATT&amp;amp;CK trend analysis.</description></item><item><title>Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework</title><link>https://fetterm4n.github.io/research/publications/splunk-model-assisted-threat-hunting-m-ath-with-the-peak-framework/</link><pubDate>Wed, 17 May 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-model-assisted-threat-hunting-m-ath-with-the-peak-framework/</guid><description>Welcome to the third entry in our introduction to the PEAK Threat Hunting Framework! Taking our detective theme to the next level, imagine a tough case where you need to call in a specialized investigator. For these unique cases, we can use algorithmically-driven approaches called Model-Assisted Threat Hunting (M-ATH).</description></item><item><title>The PEAK Threat Hunting Framework</title><link>https://fetterm4n.github.io/research/publications/peak-threat-hunting-framework/</link><pubDate>Wed, 17 May 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/peak-threat-hunting-framework/</guid><description>A structured framework for model-assisted and evidence-driven threat hunting workflows.</description></item><item><title>Paws in the Pickle Jar: Risk &amp; Vulnerability in the Model-sharing Ecosystem</title><link>https://fetterm4n.github.io/research/publications/splunk-paws-in-the-pickle-jar-risk-and-vulnerability-in-the-model-sharing-ecosystem/</link><pubDate>Thu, 27 Apr 2023 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-paws-in-the-pickle-jar-risk-and-vulnerability-in-the-model-sharing-ecosystem/</guid><description>As AI / Machine Learning (ML) systems now support millions of daily users, has our understanding of the relevant security risks kept pace with this wild rate of adoption?</description></item><item><title>Zoom. Enhance!: Finding Value in Macro-level ATT&amp;CK Reporting</title><link>https://fetterm4n.github.io/research/publications/splunk-zoom-enhance-finding-value-in-macro-level-att-and-ck-reporting/</link><pubDate>Wed, 14 Dec 2022 00:00:00 +0000</pubDate><guid>https://fetterm4n.github.io/research/publications/splunk-zoom-enhance-finding-value-in-macro-level-att-and-ck-reporting/</guid><description>Aggregated analysis of global ATT&amp;amp;CK-mapped threat reporting</description></item></channel></rss>