Detection Dispatch (Alex's Version)
Sep 1, 2026 · 1 hr 4 min · 9 segments
Pawel Mazur joins Detection Dispatch to talk about **what happens when you stop trusting detections at face value**, especially when AI is involved. From generating detection logic with an LLM to…
Paweł MazurGuestAlexHostWelcome back to Detection Dispatch, the show where we treat detections like the true scientific craft that it is.
Today's conversation covers a lot of ground where AI actually earns its keep in the detection pipeline, per se, versus where it's actually being used, why purple teaming your own lab beats trusting or deploying from your vendor's library, and why some of the best detection engineers, in my opinion, that you'll meet come from being former Linux Sysmon admins first.
My guest has strong, tested opinions on all of the three.
Paweł, welcome to the show.
I am so happy to have you here.
Detection engineers almost, I would go as far as calling it their favorite OS.
At least a lot of them, I want to

I would put actually, maybe let's say more broadly, like cybersecurity specialist OS.

However, it doesn't get much love when it comes to the detection engineering, actually.
That is true.
I did notice one of your posts that AuditD gets a lot of crap from us.
But before we get into that, we always love to know, how did you find your way into this world of detection engineering and threat hunting?
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.