11 August 2026
Incident Response
· 11 min read
A managed Mac with a clean scanner result, a genuine notarized tool holding Full Disk Access, and a LaunchAgent your persistence sweep never looked at. Here is what to read on disk when nothing was ever malicious code.
Read more →
4 August 2026
Detection & Hunting
· 11 min read
An advisory lands, you sweep the estate, nothing comes back. The tool worked perfectly and the sentence you are about to write is still wrong, because a fleet-wide result has a numerator and no denominator. Here are the queries that give you the denominator, the states check that decides whether the result is safe to read, and the finding that survives a second question.
Read more →
30 July 2026
Security Operations
· 9 min read
A playbook that completes without acting reports green on every dashboard, because skipping a step is a success. Here is the query that finds it, the four causes worth separating, and why run-success rate is the wrong measure for SOAR.
Read more →
21 July 2026
Detection Engineering
· 9 min read
Brute force and password spray produce the same failed sign-in event, so most teams try to catch both with one threshold and miss the spray entirely. A per-account count catches brute force. Only a per-source count of distinct accounts catches a spray. Here are both, written once in Sigma and rendered to KQL and SPL.
Read more →
14 July 2026
Detection Engineering
· 9 min read
A one-character field typo passes sigma check, converts to valid KQL and SPL, and silently matches nothing. Static validation proves your rule is well-formed. It cannot prove your rule works. Here's the fixture test that can, before the rule ever ships.
Read more →
7 July 2026
Security Architecture
· 14 min read
Six Active Directory defaults are still shipping in most domains and each one maps to a named 2026 attack. LAPS, NTLM and signing, Kerberos and gMSA, Protected Users, machine account quota, and the detection layer, with the exact settings and audit commands.
Read more →
2 July 2026
Detection Engineering
· 11 min read
Scheduled tasks are the most common persistence mechanism in real intrusions. Detect T1053.005 with KQL, SPL, and Sigma using the creation signal in DeviceProcessEvents and Event ID 4698, and a scoring model that separates attacker tasks from admin ones.
Read more →
30 June 2026
Identity Security
· 9 min read
ESC8 turns a coerced domain controller into a domain-wide compromise without cracking a single password. The attack leaves almost nothing on the wire, and the credential it produces outlives every account reset you'll run. Here's the chain, what it actually leaves behind, and the controls that close it.
Read more →
23 June 2026
Incident Response & Investigation
· 10 min read
GDPR, NIS2, DORA, and the SEC all start the notification clock at awareness, classification, or materiality, not at resolution. Here is when each one triggers, why investigation-first teams blow the window, and how to build the clock into triage.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
The level you need comes down to one question: what kind of information your contracts involve. Here is how to tell whether you are Level 1 or Level 2, and what each one demands.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
Your SPRS score is a number prime contractors check before they award you work. Here is how the NIST 800-171 scoring actually works, why it goes negative, and how to raise it.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A privacy notice and a cookie banner are the visible 10%. Here is the governance program underneath that GDPR, CCPA, and your enterprise customers actually check, and the documentation that proves it.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A security program rests on its policy set. Here is the documentation hierarchy, the policy domains every organization needs, and why a folder of generic templates does not survive an audit.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
The NIST Cybersecurity Framework is a framework, not a checklist. Here is how you turn the six functions into a current profile, a target profile, and a roadmap your leadership can fund.
Read more →
18 June 2026
Compliance & Audit
· 8 min read
CMMC Level 2 is won or lost on documentation, not tooling. Here is what an assessor actually checks: the SSP, the POA&M, the 110 controls, and your SPRS score.
Read more →
16 June 2026
Detection Engineering
· 10 min read
IP and domain indicators expire within days. The interval a beacon sleeps on does not. Here is how to score connection cadence to surface C2 in Sentinel and Splunk, with the coefficient-of-variation thresholds that separate a beacon from your patch agent.
Read more →
15 June 2026
Detection Engineering
· 9 min read
Alerting on AssumedRole from outside AWS buries you in SSO and automation noise. Here is the marker that isolates a stolen EC2 instance credential, and the read it gives you for free on IMDSv1 exposure.
Read more →
9 June 2026
Detection Engineering
· 9 min read
The fastest way to quiet a noisy detection rule is to exclude the field generating the noise. It's also the fastest way to cut a hole the attacker walks through. Here's how to tune by scoping to attacker behavior instead.
Read more →
4 June 2026
Detection & Hunting
· 9 min read
Ten KQL queries against SigninLogs that answer the questions SOC analysts actually ask during investigations. Copy-paste-ready with annotated output. The first 30 minutes of every identity investigation start here.
Read more →
2 June 2026
Detection Engineering
· 9 min read
Most detection libraries are full of rules that have never fired. Silent rules aren't coverage. They're assumptions. Here's how to find your silent rules, triage them, and validate the ones that matter.
Read more →
27 May 2026
Security Operations
· 11 min read
DBIR 2026: 31% of breaches start with exploitation, credentials dropped to 13%. What this means for your detection priorities.
Read more →
20 May 2026
Detection Engineering
· 12 min read
LSASS dump detection is table stakes. Kerberoasting, DCSync, DPAPI abuse, SAM extraction, and token theft each need different KQL.
Read more →
19 May 2026
Detection Engineering
· 9 min read
Most organizations can't prove their detection program works. Here's what effective looks like and the four numbers that prove it.
Read more →
16 May 2026
Detection & Hunting
· 10 min read
KQL sign-in log analysis: what ResultType values mean, how to detect password spray, MFA fatigue, and CA blocks in Sentinel.
Read more →
13 May 2026
Incident Response
· 9 min read
You're on a compromised Windows host with no forensic tools installed. Capture volatile evidence, processes, and network state using only built-in commands.
Read more →
12 May 2026
Identity Security
· 8 min read
Owning a service principal means owning its permissions. Most tenants don't monitor SP ownership changes. Here's the detection gap.
Read more →
11 May 2026
Compliance & Audit
· 11 min read
Most small companies have a security program in their heads but not on paper. RidgeGuard puts it on paper in a format auditors accept.
Read more →
9 May 2026
Compliance & Audit
· 10 min read
You don't need Vanta or Drata to pass SOC 2. Here's the documentation-first approach that works without a $30K GRC platform.
Read more →
5 May 2026
Compliance & Audit
· 9 min read
When a customer or auditor asks about your security program, you need five documents ready within 24 hours. Here's the list.
Read more →
3 May 2026
Incident Response & Investigation
· 8 min read
VanGuard: open-source DFIR toolkit that replaces the 45-minute tooling scramble at incident start. 28 use cases, cross-platform.
Read more →
3 May 2026
Incident Response & Investigation
· 10 min read
The sign-in log tells you how they got in. The audit log tells you what they did. Here's the sequence that turns both into a containment decision.
Read more →
3 May 2026
Detection Engineering
· 9 min read
Your detection rules cover known patterns. These five KQL hunts find the attacker activity that bypasses every analytics rule in your library.
Read more →
3 May 2026
Compliance & Audit
· 8 min read
Most companies lose 2-3 weeks per questionnaire because documentation isn't ready. Here's how to turn response into a same-day operation.
Read more →
30 April 2026
Security Operations
· 11 min read
BEC investigation: the queries and evidence sources you check in the first 15 minutes determine whether you catch the attacker mid-operation.
Read more →
28 April 2026
Security Operations
· 9 min read
After an AiTM token theft, the attacker's next move is often to register their own device to your tenant. Here is how to detect the pivot in Entra ID.
Read more →
28 April 2026
Security Operations
· 9 min read
Most security programs are compliance programs in disguise. Here's how to tell the difference and why it matters for your actual risk.
Read more →
21 April 2026
Security Operations
· 12 min read
Will AI replace SOC analysts? The answer is more uncomfortable than either side admits. Here's what actually changes and what doesn't.
Read more →
21 April 2026
Security Operations
· 6 min read
SSH agent forwarding becomes a lateral movement highway when a bastion host is compromised. Detection rules for auditd and Syslog.
Read more →
15 April 2026
Detection Engineering
· 7 min read
Microsoft ships 200+ Sentinel rule templates but leaves gaps in mailbox abuse, consent grants, and privilege escalation. Five rules to build.
Read more →
7 April 2026
Security Operations
· 12 min read
Most SOCs were built for threats that no longer exist. Here's what a modern SOC capability looks like and the gaps most teams carry.
Read more →
7 April 2026
Detection Engineering
· 5 min read
Most Linux rootkits load as kernel modules. Five auditd rules that detect module loading, modification, and persistence techniques.
Read more →
4 April 2026
Security Operations
· 10 min read
An E5 license is not a security strategy. What M365 security actually delivers, what it doesn't, and the gaps you need to fill.
Read more →