
Episode #11
The Detection Factory (Loop Engineering in Practice)
Tejas Paranjape joins Detection Dispatch to talk about what a detection factory can actually look like in practice and what changes when detection engineering becomes a repeatable, code driven production process rather than a collection of rules living in someone’s head. His Detection Factory breaks the work into specialized stages for writing, tuning, reviewing, testing, and shipping detections, with feedback and context carried through the process. In this episode we get into: • What a Detection Factory actually looks like and what each of its four stations does • Why detections, workflows, and infrastructure need to be represented as code if you want to automate the work • How to build quality gates and backtesting into the detection development process before anything gets shipped • Why context and institutional knowledge need to travel with the detection instead of living in the head of whoever built it • What happens when AI gets a detection mostly right but still misses something important, like an alternate log format • Why different models can have different jobs in the pipeline rather than asking one model to do everything • Where human review still matters , particularly when you are trying to catch the last few percent of problems • What workflows as code could mean for moving from detection to response at machine speed • The unexpected connection between PKI, identity, and detection engineering and why knowing what something actually is matters before you build detections around it The big picture is: “What would we have to build around it to make detection development repeatable, testable, reviewable, and trustworthy?” You can get started with ADEF here: https://github.com/Nebulock-Inc/agentic-detection-engineering-framework/blob/main/docs/methodology.md Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.






