Two Checks Passed. The Message Was Still Forged.
A pass belongs to the domain it was issued to, not the one the reader saw. Read the header for that domain, then find your own senders that fail the same way.
Read more →Blog › Security Operations
Running a SOC on the telemetry you have: triage that holds up, alert tuning, the handover that keeps an investigation alive, and the metrics that show whether the team is getting better.
10 articles
A pass belongs to the domain it was issued to, not the one the reader saw. Read the header for that domain, then find your own senders that fail the same way.
Read more →A playbook that completes without acting reports green on every dashboard, because skipping a step counts as success. Here is the query that finds it.
Read more →DBIR 2026: 31% of breaches start with exploitation, credentials dropped to 13%. What this means for your detection priorities.
Read more →BEC investigation: the queries and evidence sources you check in the first 15 minutes determine whether you catch the attacker mid-operation.
Read more →After an AiTM token theft, the attacker's next move is often to register their own device to your tenant. Here is how to detect the pivot in Entra ID.
Read more →Most security programs are compliance programs in disguise. Here's how to tell the difference and why it matters for your actual risk.
Read more →Will AI replace SOC analysts? The answer is more uncomfortable than either side admits. Here's what actually changes and what doesn't.
Read more →SSH agent forwarding becomes a lateral movement highway when a bastion host is compromised. Detection rules for auditd and Syslog.
Read more →Most SOCs were built for threats that no longer exist. Here's what a modern SOC capability looks like and the gaps most teams carry.
Read more →An E5 license is not a security strategy. What M365 security actually delivers, what it doesn't, and the gaps you need to fill.
Read more →Other topics