Building a Phishing Detection Automation: From Unfinished Business to 45-Second Analysis
Sometimes things don t go according to your plan. But sometimes, it just checks whether you have the potential or not.
Threat detection analysis and hunting walkthroughs from a SOC analyst building in public. Real datasets, real SPL, real findings.
Sometimes things don t go according to your plan. But sometimes, it just checks whether you have the potential or not.
Moving Threat Triage Upstream to Prevent Enterprise Data Exfiltration
When I built the CISA KEV Threat Intel Orchestrator, my primary goal was to solve a very specific, practical problem in security operations
49% of modern cyberattacks use PowerShell, yet attackers hide for almost a year. Here is how we used 196,000 Sysmon events to build a Sigma rule that actually catches fileless malware.
Most SOC teams only watch process creation. Today, we're tracking what processes load to catch advanced adversaries before they execute.
How I built a zero-touch pipeline that completely automates CISA KEV tracking and Sigma rule generation.
Nothing ever goes as we planned in this accursed world.
The detection rule I built.
Why a decades old Windows behavior is powerful tool to APT's
Why experienced threat hunters pivot on process context instead of chasing individual EventIDs
49% of cyberattacks use PowerShell somewhere in the kill chain. Most security teams can't tell when it's being abused.
Detects Powershell.exe or cmd.exe accessing lsass.exe with full or near full access rights.
Inside The Breach #4
Inside The Breach #3
Inside The Breach #3
Inside the Breach #1
Understanding the theory before analyzing real attack logs
I built Splunk queries in my lab.
They re hiding in plain sight in your logs.
I analyzed real malware logs and discovered why non-admin users can execute code without triggering a single alert.