Workshop by Douglas Leece and Veljko Mojic
Detection engineers and incident responders are often handed unfamiliar artifacts under time pressure: a SaaS audit export, firewall log, PCAP, endpoint trace, cloud activity record, vendor threat report, or a bundle of evidence from a system nobody has fully onboarded. Before that data can become useful detection content, someone has to understand what it contains, whether it has security value, and how it relates to real attacker behavior.
Event Mill is an open-source, extensible framework for that messy middle ground. It is not a SIEM, SOAR, alerting platform, or real-time collector. It is closer to a field kit for detection engineering and incident response: a place to build, run, and share purpose-built tools that help analysts turn unfamiliar telemetry and threat intelligence into structured investigative knowledge.
In the workshop, we will cover Event Mill’s framework, plugin, and routing architecture. Inspired by extensible security toolkits such as Metasploit and SET, Event Mill uses self-describing plugins organized around investigation pillars, including log analysis, network forensics, threat modeling, and cloud investigation.
We will also cover one of the enhancements identified during Event Mill’s early development: a context-management strategy that helps the LLM understand the operating environment surrounding the data it is analyzing. Is this a routine threat-hunting activity where administrative behavior should be expected, or are you investigating a suspected breach and need the model to take a more cautious perspective? Event Mill can tailor the model context accordingly, while the routing layer helps align the workload with an appropriate LLM model.
In the workshop, participants will use Event Mill to triage unfamiliar event sources, summarize useful fields, analyze PCAPs for incident-response context, and ingest threat intelligence reports to generate attack chains aligned to adversary behavior. These outputs can help teams move toward Cyber Threat Informed Detection by connecting raw evidence, attacker tradecraft, and detection engineering decisions.
In the second half of the workshop, we will move beyond using the platform and look at how to extend it. Participants will see how new analysis skills, tools, and data-processing capabilities can be added to Event Mill, including examples of improving LLM-assisted analysis and building deterministic tools for security data transformation.
Date: Friday, September 25, 2026
Time: 10:40am-12:30pm
PIC 234
Pre-registation is required for this workshop.
Get your workshop ticket through Eventbrite
Your contact information will be shared with the instructors.
Democratizing Detection Engineering with open source & AI
A pain point in their day job, an interest in AI, and cloud computing led two co-workers, Doug Leece and Veljko Mojic down a path where they are two maintainers of Event Mill, an open-source project designed to address a common gap in the detection engineering workflow.
More than 40 years of collective experience, Mojic and Leece are well versed in both cyber security as well as telephony and ITC engineering.
Democratizing Detection Engineering with open source & AI
Veljko Mojic is a security engineer specializing in incident response, threat hunting, and enterprise security operations. With experience working in large enterprise environments, he focuses on building practical tooling and workflows that help analysts identify and investigate threats more efficiently across modern infrastructure.