Hi! ๐ Iโm Ian Hanley.
Iโm a security researcher, engineer, author, and lifelong tinkerer who likes figuring out how security systems behave once they leave the whiteboard and meet the real world.
My background spans detection engineering, threat intelligence, telemetry architecture, Microsoft security platforms, security automation, and increasingly AI and LLM evaluation. A lot of what I work on revolves around a deceptively simple question:
Does this actually work in production?
That means testing detections against messy telemetry, investigating why perfectly valid queries return the wrong answer, evaluating AI-assisted security workflows, automating threat research, breaking assumptions, and building systems that can operate at machine speed without losing the context and judgment defenders depend on.
Iโm the author of Ultimate Microsoft XDR for Full Spectrum Cyber Defense, KQL Toolbox, and PowerShell Toolbox.
DevSecOpsDad.com is where I publish what I learn along the way: practical KQL, detection engineering, security research, automation, AI experimentation, and the occasional deep dive into something that behaved very differently than it was supposed to.
I also run DevSecOpsDadAttack.com, where much of that work has evolved into automated threat intelligence, detection engineering research, and a growing open KQL detection library.
Outside of all of that, Iโm a husband and dad. Parenthood has provided more hands-on experience with incident response, chaos engineering, and risk management than any certification ever could. ๐
โก You can also find me on LinkedIn.
Cheers, Ian D. Hanley