22 September 2026
Security Operations
· 9 min read
A pass belongs to the domain it was issued to, not the one the reader saw. Read the header for that domain, then find your own senders that fail the same way.
Read more →
15 September 2026
Incident Response
· 9 min read
A quiet hour in the logs has five ordinary causes before it has a suspicious one. Work them in order, and know a positive tell when you see it.
Read more →
12 September 2026
Incident Response
· 8 min read
A process can rewrite what ps reports about it in three lines of C. One field on the same host cannot be rewritten, and the contradiction is the detection.
Read more →
1 September 2026
Incident Response
· 9 min read
The setting that decides whether you recover a SharePoint library is one any site owner can change. Detection in KQL, SPL and Sigma.
Read more →
25 August 2026
Identity Security
· 8 min read
An Entra ID app registration holds a list of client secrets, not a value. Rotation adds one and removes nothing unless somebody does it deliberately.
Read more →
11 August 2026
Incident Response
· 11 min read
A managed Mac, a clean scanner result, and a notarized tool holding Full Disk Access. What to read on disk when nothing was ever technically malware.
Read more →
4 August 2026
Detection Engineering
· 11 min read
An advisory lands, you sweep the estate, nothing comes back. A fleet-wide clean result has a numerator and no denominator, which is not the same as safe.
Read more →
30 July 2026
Security Operations
· 9 min read
A playbook that completes without acting reports green on every dashboard, because skipping a step counts as success. Here is the query that finds it.
Read more →
21 July 2026
Detection Engineering
· 9 min read
Brute force and password spray produce the same failed sign-in event. A per-account threshold catches one and misses the other entirely.
Read more →
14 July 2026
Detection Engineering
· 9 min read
A one-character field typo passes sigma check, converts to valid KQL and SPL, and matches nothing. Static validation cannot prove a rule works.
Read more →
7 July 2026
Security Architecture
· 14 min read
Six Active Directory defaults still shipping in most domains, each mapping to a named 2026 attack: LAPS, NTLM signing, Kerberos, gMSA and machine quota.
Read more →
2 July 2026
Detection Engineering
· 11 min read
Detect T1053.005 scheduled task persistence with KQL, SPL and Sigma, using Event ID 4698 and a scoring model that separates attacker tasks from admin ones.
Read more →
30 June 2026
Identity Security
· 9 min read
ESC8 turns a coerced domain controller into domain-wide compromise with no password cracked, and the certificate it issues outlives your password reset.
Read more →
23 June 2026
Incident Response
· 10 min read
GDPR, NIS2, DORA and the SEC start the notification clock at awareness or materiality, not at resolution. When each triggers, and why teams miss it.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
The CMMC level you need comes down to one question: what kind of information your contracts involve. Here is how to tell, and what each level demands.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
Your SPRS score is a number prime contractors check before awarding work. How NIST 800-171 scoring works, why it goes negative, and how to raise it.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A privacy notice and a cookie banner are the visible 10 per cent. Here is the governance program underneath that GDPR, CCPA and enterprise buyers check.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A security program rests on its policy set. The documentation hierarchy, the domains you need, and why generic templates do not survive an audit.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
The NIST Cybersecurity Framework is a framework, not a checklist. How to turn the six functions into a current profile, a target, and a funded roadmap.
Read more →
18 June 2026
Compliance & Audit
· 8 min read
CMMC Level 2 is won or lost on documentation, not tooling. Here is what an assessor actually checks: the SSP, the POA&M, the 110 controls, and your SPRS score.
Read more →
16 June 2026
Detection Engineering
· 10 min read
IP and domain indicators expire within days. The interval a beacon sleeps on does not. How to score connection cadence in Sentinel and Splunk.
Read more →
15 June 2026
Detection Engineering
· 9 min read
Alerting on AssumedRole from outside AWS buries you in SSO noise. Here is the marker that isolates a stolen EC2 instance credential from the rest.
Read more →
9 June 2026
Detection Engineering
· 9 min read
The fastest way to quiet a noisy rule is to exclude the field making the noise. It is also the fastest way to cut a hole the attacker walks through.
Read more →
4 June 2026
Detection Engineering
· 9 min read
Ten KQL queries against SigninLogs that answer what SOC analysts actually ask during an identity investigation, copy-paste ready with annotated output.
Read more →
2 June 2026
Detection Engineering
· 9 min read
Most detection libraries are full of rules that have never fired. Silent rules are not coverage, they are assumptions. How to find and validate them.
Read more →
27 May 2026
Security Operations
· 11 min read
DBIR 2026: 31% of breaches start with exploitation, credentials dropped to 13%. What this means for your detection priorities.
Read more →
20 May 2026
Detection Engineering
· 12 min read
LSASS dump detection is table stakes. Kerberoasting, DCSync, DPAPI abuse, SAM extraction, and token theft each need different KQL.
Read more →
19 May 2026
Detection Engineering
· 9 min read
Most organizations can't prove their detection program works. Here's what effective looks like and the four numbers that prove it.
Read more →
16 May 2026
Detection Engineering
· 10 min read
KQL sign-in log analysis: what ResultType values mean, how to detect password spray, MFA fatigue, and CA blocks in Sentinel.
Read more →
13 May 2026
Incident Response
· 9 min read
You're on a compromised Windows host with no forensic tools installed. Capture volatile evidence, processes, and network state using only built-in commands.
Read more →
12 May 2026
Identity Security
· 8 min read
Owning a service principal means owning its permissions. Most tenants don't monitor SP ownership changes. Here's the detection gap.
Read more →
11 May 2026
Compliance & Audit
· 11 min read
Most small companies have a security program in their heads but not on paper. RidgeGuard puts it on paper in a format auditors accept.
Read more →
9 May 2026
Compliance & Audit
· 10 min read
You don't need Vanta or Drata to pass SOC 2. Here's the documentation-first approach that works without a $30K GRC platform.
Read more →
5 May 2026
Compliance & Audit
· 9 min read
When a customer or auditor asks about your security program, you need five documents ready within 24 hours. Here's the list.
Read more →
3 May 2026
Incident Response
· 8 min read
VanGuard: open-source DFIR toolkit that replaces the 45-minute tooling scramble at incident start. 28 use cases, cross-platform.
Read more →
3 May 2026
Incident Response
· 10 min read
The sign-in log tells you how they got in. The audit log tells you what they did. Here's the sequence that turns both into a containment decision.
Read more →
3 May 2026
Detection Engineering
· 9 min read
Your detection rules cover known patterns. These five KQL hunts find the attacker activity that bypasses every analytics rule in your library.
Read more →
3 May 2026
Compliance & Audit
· 8 min read
Most companies lose 2-3 weeks per questionnaire because documentation isn't ready. Here's how to turn response into a same-day operation.
Read more →
30 April 2026
Security Operations
· 11 min read
BEC investigation: the queries and evidence sources you check in the first 15 minutes determine whether you catch the attacker mid-operation.
Read more →
28 April 2026
Security Operations
· 9 min read
After an AiTM token theft, the attacker's next move is often to register their own device to your tenant. Here is how to detect the pivot in Entra ID.
Read more →
28 April 2026
Security Operations
· 9 min read
Most security programs are compliance programs in disguise. Here's how to tell the difference and why it matters for your actual risk.
Read more →
21 April 2026
Security Operations
· 12 min read
Will AI replace SOC analysts? The answer is more uncomfortable than either side admits. Here's what actually changes and what doesn't.
Read more →
21 April 2026
Security Operations
· 6 min read
SSH agent forwarding becomes a lateral movement highway when a bastion host is compromised. Detection rules for auditd and Syslog.
Read more →
15 April 2026
Detection Engineering
· 7 min read
Microsoft ships 200+ Sentinel rule templates but leaves gaps in mailbox abuse, consent grants, and privilege escalation. Five rules to build.
Read more →
7 April 2026
Security Operations
· 12 min read
Most SOCs were built for threats that no longer exist. Here's what a modern SOC capability looks like and the gaps most teams carry.
Read more →
7 April 2026
Detection Engineering
· 5 min read
Most Linux rootkits load as kernel modules. Five auditd rules that detect module loading, modification, and persistence techniques.
Read more →
4 April 2026
Security Operations
· 10 min read
An E5 license is not a security strategy. What M365 security actually delivers, what it doesn't, and the gaps you need to fill.
Read more →