Daniel Andrawis
Detection engineer in New York. I build detection content for LLM abuse, and then test whether it actually works, which is usually the more interesting half.
Writing
I tested my own detection rule and it failed
A 2023 jailbreak phrase list, 126 trials against a 2026 model, and a third outcome the experiment did not anticipate.
1 September 2026
Projects
detection-llm-misuse
Provider-side detection content for abuse of LLM inference APIs. Sigma and Google SecOps YARA-L, mapped to MITRE ATLAS, with synthetic fixtures and CI. Every rule carries a dated experiment saying whether it still detects a live technique.
Open source, MIT
ioc-enrich
Multi-source IOC enrichment for analyst triage. VirusTotal, urlscan, and Censys, with provenance on every claim and a hard rule that it never reports "not found" when it actually failed to look.
Open source, MIT
Elsewhere
GitHub
Built as static HTML. No trackers, no analytics.