Insights & Guides

The Attacks You'll Investigate. The Detections You'll Write. The Decisions You'll Defend.

Practical analysis of real attack patterns, detection techniques, identity security, and operational judgment, written by the professionals who build the courses. Every post teaches something you can apply at work this week.

Browse by Topic ↓ All Posts Unlock the Full Course →
Latest The Mac With No Malware On It: When Consent Is the Attack Path 11 August 2026 · Incident Response · 11 min read A managed Mac with a clean scanner result, a genuine notarized tool holding Full Disk Access, and a LaunchAgent your persistence sweep never looked at. Here is what to read on disk when nothing was ever malicious code. Read post →

Threat Detection Engineering

Detection rules, coverage analysis, and the engineering practices that turn ad-hoc queries into a sustainable detection program.

One Failed Login Is Noise. The Same Failure Across Sixty Accounts Is a Spray Your Rule Can't Count. Your Sigma Rule Converts Cleanly and Still Never Fires. Here's the Test That Catches It. Core Security Settings to Secure Your Active Directory Environment Detecting Malicious Scheduled Tasks: The Persistence That Survives Your Cleanup The EC2 Credential-Theft Detection Most Teams Ship Wrong Your Noisy Rule Has 200 False Positives a Day. Don't Suppress the Field That's Making Noise. You Deployed 350 Detection Rules. Only 50 Fire Regularly. Are the Other 300 Working? Vulnerability Exploitation Just Overtook Credential Theft as the #1 Breach Vector. But Is It Really This Bad? Credential Access Detection Beyond LSASS, The Five Techniques Your Rules Are Missing Is Your Detection Program Effective? And How Would You Know? KQL Sign-In Log Analysis, What ResultType != 0 Actually Tells You Service Principal Ownership Is the Attack Path Nobody Governs Five KQL Threat Hunts Every M365 SOC Should Run This Month How Attackers Pivot Through SSH Agent Forwarding, and How to Detect It The M365 Detections Microsoft Doesn't Give You Five auditd Rules That Catch Kernel Module Rootkits Before They Load

The blog shows you what's possible. The courses make you capable.

Every technique, detection rule, and investigation method referenced in these posts is taught in depth across the course catalog. Start with the course preview.

Unlock the Full Course Browse All Courses