Marta Kowalska

Marta K.

Senior Detection Engineer & Incident Responder

Marta K. is a senior detection engineer and incident responder with over eight years of hands-on experience operating and scaling security operations in high-growth SaaS and fintech environments. She started her career as a SOC analyst, working night shifts triaging alerts and investigating suspicious activity across endpoint, identity, and cloud environments. Over time, she moved into detection engineering, where she focused on building and tuning detection pipelines, reducing false positives, and mapping coverage to frameworks like MITRE ATT&CK. Marta has led incident response efforts for ransomware, credential compromise, and insider threat scenarios, and has helped teams transition from reactive alert handling to structured investigation workflows and proactive detection strategies. Her work has included implementing detection-as-code practices, improving alert fidelity, and designing playbooks that actually get used during real incidents. She writes about the reality of running security operations — from alert fatigue and broken escalation paths to what actually works when building detections and responding to incidents under pressure.

Articles

Phishing & Social Engineering Defense

Social engineering patterns we've seen get past filters

The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all.

Jul 25, 2026

AI in Security Operations

How AI-assisted investigation actually walks through a Tier 1 alert

Impossible travel on a finance account used to eat half an hour of my night, walking four consoles by hand to prove it was just a VPN. With an AI-assisted tool the enrichment was already assembled when the case reached me, so I started where the work needs a person. The AI compressed the mechanical parts, and I kept every judgment call.

Jul 25, 2026

Identity & Access Security Operations

MFA fatigue attacks: what the security SOC sees, what the user clicks

The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both.

Jul 17, 2026

Incident Response

How to run an incident response tabletop that isn't theater

Three years ago I sat through an incident response tabletop that was pure theater: the scenario was circulated a week early, everyone read their lines, and someone ticked a compliance box. Six months later a real credential compromise broke everything the exercise had supposedly validated. A tabletop that can't be failed can't teach anything, and most are built exactly that way.

Jul 17, 2026

Threat Hunting

What threat hunters actually do on a Tuesday

Threat hunters spend Tuesday testing one written hypothesis against messy data, not browsing logs for fun. The real output is a shipped detection or a documented gap, even when the hunt finds nothing.

Jul 11, 2026

Phishing & Social Engineering Defense

What vishing looks like from the SOC triage seat

Vishing hides in identity logs, not email or endpoint alerts, so the SOC sees the aftermath first. The real signal is a correlated trail: help-desk reset, risky re-enrollment, then anomalous sign-in.

Jul 10, 2026

Phishing & Social Engineering Defense

Smishing in 2026: where the attacks are actually landing

Smishing hasn't stayed in the consumer fraud category it started in. The SMS attacks showing up in enterprise queues in 2026 are multi-stage credential harvesting campaigns: IT helpdesk impersonation, MFA code interception, RCS delivery that bypasses carrier filters. Most SOC tooling wasn't built to catch any of it.

Jul 4, 2026

Detection Engineering

What detection engineers actually do (job description vs. reality)

The detection engineer job description says: write detection rules, map to ATT&CK, tune false positives. Most of what the role actually requires (debugging broken log pipelines, maintaining exclusion lists nobody documented, writing the investigation context that keeps a detection actionable months after it ships) never makes it into the posting.

Jul 4, 2026

Phishing & Social Engineering Defense

What a phishing investigation actually looks like in 2026

A user-reported phish looked dead on arrival: clean sandbox, benign PDF, expired URL. The real compromise was already live in the identity plane as a replayed session token and an attacker-created OAuth grant, three hours before the runbook caught up.

Jun 26, 2026

AI in Security Operations

I ran three AI SOC tools on the same alert stream: Here’s what happened

I ran Prophet Security, Dropzone AI, and 7AI against 30 days of real production alerts instead of a curated demo, and the three diverged far more than the marketing suggests. The widest gaps showed up on the ambiguous cases, where the tool that scored best on raw accuracy turned out to be the weakest at explaining itself.

Jun 19, 2026

Detection Engineering

The 20 detections worth building before anything else

A green ATT&CK heatmap measures how many rules you've written, not whether any of them work. Start with the 20 detections that show up most often in real breach chains, validate each one, and only then expand.

Jun 19, 2026

AI in Security Operations

What an AI SOC agent actually does on a Tier 1 alert

An AI SOC agent closed an impossible-travel alert with a full evidence chain in under four minutes. It also recommended isolating a production server over clean traffic the same week. Marta Kowalska walks one real Entra ID alert through the agent's full investigation chain — and shows exactly where the reasoning broke on a different alert class.

Jun 15, 2026

AI in Security Operations

Most autonomous SOC pitches don't survive a real alert stream

The autonomous SOC demo cleared 40 curated alerts in under two minutes. Four hours into a real production queue on a Wednesday night, it had already stalled on a custom cloud detection, silently closed a dedup cluster, and skipped an alert that needed a Jira ticket to answer.

Jun 5, 2026

Detection Engineering

What we got wrong in our first 100 detections

We shipped a hundred detections and the ATT&CK heatmap stayed green through fourteen broken rules, week-stale IOCs, and a log pipeline that had stopped exporting months earlier. Every failure traced to the same root: we treated detection engineering as rule writing and skipped the maintenance.

Jun 5, 2026

MDR

What an MDR renewal conversation actually sounds like

Most MDR vendors arrive at renewal with a polished QBR deck. Most customers arrive with nothing to push back with. That asymmetry is the whole game — and it's why flat escalation rates, unaudited closed verdicts, and a 2 AM analyst who knows nothing about your environment survive contract after contract. This piece is the counter-metric.

Jun 5, 2026

Detection Engineering

Sigma rules are essential, and also overrated

Sigma solved detection portability but not tuning, conversion fidelity, or cloud coverage. Where the format still delivers value and where teams over-rely on it.

Jun 3, 2026

Cloud Security Operations

What cloud security monitoring actually looks like in a mid-market SOC

Cloud security monitoring for 3-5 person SOC teams: four pillars, co-managed MDR, telemetry strategy, and where most stacks fail.

Jun 2, 2026

Detection Engineering

What we got wrong about purple teaming in our first year

Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it.

May 25, 2026

AI in Security Operations

Alert fatigue won't be solved by AI alone

AI triage hasn't moved alert fatigue. The structural causes start upstream. Here's what to fix before another AI SOC pilot.

May 12, 2026

Detection Engineering

Detection engineering is a function, not a headcount

Detection engineering stalls when it's treated as a person, not a function. Here's what the function actually owns, and how to build it from Level 0.

May 11, 2026

Incident Response

What a usable incident response plan looks like (with a template)

Most IRPs are written for auditors, not analysts. Here's what a usable incident response plan actually contains, plus a stripped-down template.

May 10, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Marta K. | Future of SecOps