23 June 2026
Incident Response & Investigation
· 10 min read
GDPR, NIS2, DORA, and the SEC all start the notification clock at awareness, classification, or materiality, not at resolution. Here is when each one triggers, why investigation-first teams blow the window, and how to build the clock into triage.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
The level you need comes down to one question: what kind of information your contracts involve. Here is how to tell whether you are Level 1 or Level 2, and what each one demands.
Read more →
18 June 2026
Compliance & Audit
· 7 min read
Your SPRS score is a number prime contractors check before they award you work. Here is how the NIST 800-171 scoring actually works, why it goes negative, and how to raise it.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A privacy notice and a cookie banner are the visible 10%. Here is the governance program underneath that GDPR, CCPA, and your enterprise customers actually check, and the documentation that proves it.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
A security program rests on its policy set. Here is the documentation hierarchy, the policy domains every organization needs, and why a folder of generic templates does not survive an audit.
Read more →
18 June 2026
Compliance & Audit
· 9 min read
The NIST Cybersecurity Framework is a framework, not a checklist. Here is how you turn the six functions into a current profile, a target profile, and a roadmap your leadership can fund.
Read more →
18 June 2026
Compliance & Audit
· 8 min read
CMMC Level 2 is won or lost on documentation, not tooling. Here is what an assessor actually checks: the SSP, the POA&M, the 110 controls, and your SPRS score.
Read more →
16 June 2026
Detection Engineering
· 10 min read
IP and domain indicators expire within days. The interval a beacon sleeps on does not. Here is how to score connection cadence to surface C2 in Sentinel and Splunk, with the coefficient-of-variation thresholds that separate a beacon from your patch agent.
Read more →
15 June 2026
Detection Engineering
· 9 min read
Alerting on AssumedRole from outside AWS buries you in SSO and automation noise. Here is the marker that isolates a stolen EC2 instance credential, and the read it gives you for free on IMDSv1 exposure.
Read more →
9 June 2026
Detection Engineering
· 9 min read
The fastest way to quiet a noisy detection rule is to exclude the field generating the noise. It's also the fastest way to cut a hole the attacker walks through. Here's how to tune by scoping to attacker behaviour instead.
Read more →
4 June 2026
Detection & Hunting
· 9 min read
Ten KQL queries against SigninLogs that answer the questions SOC analysts actually ask during investigations. Copy-paste-ready with annotated output. The first 30 minutes of every identity investigation start here.
Read more →
2 June 2026
Detection Engineering
· 9 min read
Most detection libraries are full of rules that have never fired. Silent rules aren't coverage. They're assumptions. Here's how to find your silent rules, triage them, and validate the ones that matter.
Read more →
27 May 2026
Security Operations
· 11 min read
DBIR 2026: 31% of breaches start with exploitation, credentials dropped to 13%. What this means for your detection priorities.
Read more →
20 May 2026
Detection Engineering
· 12 min read
LSASS dump detection is table stakes. Kerberoasting, DCSync, DPAPI abuse, SAM extraction, and token theft each need different KQL.
Read more →
19 May 2026
Detection Engineering
· 9 min read
Most organizations can't prove their detection program works. Here's what effective looks like and the four numbers that prove it.
Read more →
16 May 2026
Detection & Hunting
· 10 min read
KQL sign-in log analysis: what ResultType values mean, how to detect password spray, MFA fatigue, and CA blocks in Sentinel.
Read more →
13 May 2026
Incident Response
· 9 min read
Read more →
12 May 2026
Identity Security
· 8 min read
Owning a service principal means owning its permissions. Most tenants don't monitor SP ownership changes. Here's the detection gap.
Read more →
11 May 2026
Compliance & Audit
· 11 min read
Most small companies have a security program in their heads but not on paper. RidgeGuard puts it on paper in a format auditors accept.
Read more →
9 May 2026
Compliance & Audit
· 10 min read
You don't need Vanta or Drata to pass SOC 2. Here's the documentation-first approach that works without a $30K GRC platform.
Read more →
5 May 2026
Compliance & Audit
· 9 min read
When a customer or auditor asks about your security program, you need five documents ready within 24 hours. Here's the list.
Read more →
3 May 2026
Incident Response & Investigation
· 8 min read
VanGuard: open-source DFIR toolkit that replaces the 45-minute tooling scramble at incident start. 28 use cases, cross-platform.
Read more →
3 May 2026
Incident Response & Investigation
· 10 min read
The sign-in log tells you how they got in. The audit log tells you what they did. Here's the sequence that turns both into a containment decision.
Read more →
3 May 2026
Detection Engineering
· 9 min read
Your detection rules cover known patterns. These five KQL hunts find the attacker activity that bypasses every analytics rule in your library.
Read more →
3 May 2026
Compliance & Audit
· 8 min read
Most companies lose 2-3 weeks per questionnaire because documentation isn't ready. Here's how to turn response into a same-day operation.
Read more →
30 April 2026
Security Operations
· 11 min read
BEC investigation: the queries and evidence sources you check in the first 15 minutes determine whether you catch the attacker mid-operation.
Read more →
28 April 2026
Security Operations
· 9 min read
After an AiTM token theft, the attacker's next move is often to register their own device to your tenant. Here is how to detect the pivot in Entra ID.
Read more →
28 April 2026
Security Operations
· 9 min read
Most security programs are compliance programs in disguise. Here's how to tell the difference and why it matters for your actual risk.
Read more →
21 April 2026
Security Operations
· 12 min read
Will AI replace SOC analysts? The answer is more uncomfortable than either side admits. Here's what actually changes and what doesn't.
Read more →
21 April 2026
Security Operations
· 6 min read
SSH agent forwarding becomes a lateral movement highway when a bastion host is compromised. Detection rules for auditd and Syslog.
Read more →
15 April 2026
Detection Engineering
· 7 min read
Microsoft ships 200+ Sentinel rule templates but leaves gaps in mailbox abuse, consent grants, and privilege escalation. Five rules to build.
Read more →
7 April 2026
Security Operations
· 12 min read
Most SOCs were built for threats that no longer exist. Here's what a modern SOC capability looks like and the gaps most teams carry.
Read more →
7 April 2026
Detection Engineering
· 5 min read
Most Linux rootkits load as kernel modules. Five auditd rules that detect module loading, modification, and persistence techniques.
Read more →
4 April 2026
Security Operations
· 10 min read
An E5 license is not a security strategy. What M365 security actually delivers, what it doesn't, and the gaps you need to fill.
Read more →