Daniel Andrawis

Detection engineer in New York. I build detection content for LLM abuse, and then test whether it actually works, which is usually the more interesting half.

Writing

I tested my own detection rule and it failed A 2023 jailbreak phrase list, 126 trials against a 2026 model, and a third outcome the experiment did not anticipate. 1 September 2026

Projects

detection-llm-misuse Provider-side detection content for abuse of LLM inference APIs. Sigma and Google SecOps YARA-L, mapped to MITRE ATLAS, with synthetic fixtures and CI. Every rule carries a dated experiment saying whether it still detects a live technique. Open source, MIT ioc-enrich Multi-source IOC enrichment for analyst triage. VirusTotal, urlscan, and Censys, with provenance on every claim and a hard rule that it never reports "not found" when it actually failed to look. Open source, MIT

Elsewhere

GitHub