Rocky the cyber security raccoon

AI built for detection engineering

I'm Rocky, the Cyber Raccoon.

Your trash-panda-shaped unfair advantage for detection engineering: writing and tuning detections, hunting, and making sense of Windows process behavior. I beat a generalist chatbot where it counts, because I'm current, exact, and I cite my sources.

The Backstory

You might remember EchoTrail Insights, that dataset of millions of Windows process executions collected over years across real-world endpoints. Behavioral baselines for thousands of unique executables. Parent-child relationships, command-line patterns, network activity, file operations, the works.

I got my paws on all of it. So when I tell you how a process behaves, I'm not guessing, I'm pulling from real-world observation.

But I didn't stop there. A pile of process data doesn't help you write a detection if the detection knowledge in your AI's head is two years stale. So I also feed on living detection knowledge that refreshes itself:

  • SigmaHQ: the full detection ruleset, thousands of rules.
  • LOLBAS: the catalog of trusted Windows binaries that attackers abuse to live off the land.
  • MITRE ATT&CK: the entire knowledge base, every technique, group, and piece of malware, with the detection strategies and mitigations wired in.
  • Atomic Red Team: Red Canary's ~1,800 adversary-emulation tests, with the exact commands to validate your detections.
  • CISA KEV: the Known Exploited Vulnerabilities catalog, ~1,600 CVEs confirmed exploited in the wild, flagged when they're tied to ransomware.

All re-synced weekly and cited inline so you can check my work. More sources are coming. A generalist LLM is frozen at its training cutoff; I'm not.

What I Actually Do

I help you build and reason about detections, grounded in current rules and real behavior. Specifically:

  • Detection content: Need a rule? I'll help you write or tune one against the real SigmaHQ corpus and real process behavior, not a theoretical attack scenario, with the source linked.
  • Process behavior analysis: Is this executable doing something unusual? I'll tell you how it typically behaves across millions of observations.
  • Threat hunting: I'll help you build hypotheses and queries that surface the anomalies that actually matter, based on statistical baselines.
  • LOLBin reasoning: Living-off-the-land binaries are my specialty. I know what normal looks like, which means I know what abnormal looks like too. Now grounded in the LOLBAS catalog, re-synced weekly and cited.

Everything I point to, I can source. Not vibes. Not a half-remembered blog post. Real rules and real data.

Who I'm For

If your job touches detections, writing them, tuning them, or just understanding what a rule actually does, I'm for you. That's a lot more people than the few with “detection engineer” on their badge.

  • SOC analysts: Staring at an alert and need to know whether this process behavior is normal? I've got an answer in seconds, backed by real execution data. Want to understand or tune the rule that fired? I'll walk you through it with the source in hand.
  • Threat hunters: You need hypotheses worth pursuing. I'll help you find the anomalies that matter, not the ones that waste your afternoon.
  • Detection engineers: Writing rules without behavioral baselines is like coding without tests. I'll give you current reference content and the data to build detections that hold up in production.
  • The SOC or detection lead: I'm how you stop all the detection knowledge living in one or two people's heads. Level your tier-1s and tier-2s up toward reading and writing detections, keep the whole team current on fresh, cited threat knowledge, and ramp new hires faster.

Try Me Out

Not sure where to start? Ask me:

What Makes Me Different

Plenty of AI security tools out there. Here's why I'm not like them:

  • Always current. A generalist LLM is frozen at its training cutoff and answers in generalities. I re-sync my detection knowledge weekly, so I'm right where the others are stale.
  • Cited, not vibes. When an answer is grounded, it links its source. You get something you can verify and put in a report, not a hunch from a chatbot.
  • Real prevalence data. When I say a behavior is unusual, I can tell you exactly how unusual. Percentiles, frequencies, baseline comparisons, from millions of real Windows executions.
  • Built on Claude. Anthropic's models give me the reasoning; the fresh corpus and the dataset give me the domain expertise to use it well.

Pricing

Start free: 10 questions a day, no card required. Enough to kick the tires and see if I'm worth your time (I am).

When your team runs on me daily, there are plans for that. Tell me about your team and we'll sort it out.

Privacy

Your conversations are yours. I don't use them to train AI models. Your card details, when there are any, are handled by a payment processor; I never see or store them. I keep things simple and private.

Want the full legal version? Read the privacy policy.

The Human Behind the Raccoon

I'm Brian Concannon, and I built Rocky myself. 20+ years in cybersecurity: FBI, CrowdStrike, Expel, and now detection-engineering consulting through EchoTrail Solutions. I spent years building the EchoTrail dataset and realized it could be far more useful with the right AI on top of it. No VC funding, no board, no growth-at-all-costs. Here's what that means for you:

  • Your data stays yours. I will never sell it. Your conversations, queries, and usage patterns don't get monetized behind your back. I built Rocky to help security practitioners, not to harvest their work.
  • Your feedback shapes the product. Rocky is built in public, driven by what real users actually need. I read every piece of feedback personally. Want a feature? Tell me. Something broken? Tell me. It goes straight to the person writing the code.
  • Detection engineering is the north star. Rocky is built to be genuinely good at developing and tuning detections grounded in real data and current rules. Hunting, triage, IR, anywhere process behavior and detection logic matter, it should earn its keep.
  • Rocky grows through the community, not sales tactics. No spam, no pressure. If Rocky's good, you'll tell your colleagues. If it's not good enough yet, tell me what to fix. I'd rather have a small community that finds real value than a big list that signed up and forgot.

The best way to support Rocky is to use him, share feedback, and bring your team along if he saves you time.

Enough reading. Let's go dig through some data.

Start Chatting with Rocky