# mandiant (blogs) — RSS Amplifier

Recent posts from the 2 feeds in the RSS Amplifier directory that cover mandiant.

Page: <https://rssamplifier.com/topics/mandiant/blogs>  
Feed: <https://rssamplifier.com/topics/mandiant/blogs.md>

---

## [FreeBSD Released the Most Security Advisories in Project History in June 2026](https://taosecurity.blogspot.com/2026/07/freebsd-released-most-security.html)

_2026-07-17 · Richard Bejtlich · TaoSecurity Blog_

On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, with 6 powered by AI . In May, the count decreased slightly to 7. Today I took a look at the FreeBSD Security Advisory page to check the latest advisory count. June saw the most number of advisories ever published in project history: 25. This blows…

## [I Wrote a New Book for Corelight](https://taosecurity.blogspot.com/2026/07/i-wrote-new-book-for-corelight.html)

_2026-07-09 · Richard Bejtlich · TaoSecurity Blog_

TLDR: I wrote a new book for Corelight called NDR Essentials . It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com . Why? It was time . That’s what I thought when I heard that Corelight wanted to update its 2021 book on network detection and response (NDR). Tamara Crawford, who owned the project, scheduled a meeting with me…

## [Bill to Create Independent US Cyber Force Wants to Place It Under the US Army](https://taosecurity.blogspot.com/2026/06/bill-to-create-independent-us-cyber.html)

_2026-06-08 · Richard Bejtlich · TaoSecurity Blog_

It looks like we're finally making progress towards an independent US Cyber Force: https://www.csis.org/programs/strategic-technologies-program/projects/commission-us-cyber-force-generation However, this bill by Sen Gillibrand to put it under the Army isn't the best idea. https://www.airandspaceforces.com/new-push-for-separate-cyber-force-builds-but-questions-remain/ I get it -- Navy has the…

## [Mandiant Global Median Dwell Time Deteriorates from 11 to 14 Days](https://taosecurity.blogspot.com/2026/03/mandiant-global-median-dwell-time.html)

_2026-03-24 · Richard Bejtlich · TaoSecurity Blog_

Oh snap. My single most important cybersecurity metric deteriorated again. In the M-Trends report for calendar year 2024, Mandiant’s global median dwell time metric worsened from 10 to 11 days. In the newest report, released today, for calendar year 2025, that metric worsened again, from 11 to 14 days. In other words, organizations are taking even longer to detect and respond to intrusions. 10…

## [Happy 23rd Birthday TaoSecurity Blog](https://taosecurity.blogspot.com/2026/01/happy-23rd-birthday-taosecurity-blog.html)

_2026-01-08 · Richard Bejtlich · TaoSecurity Blog_

Happy birthday TaoSecurity Blog, born on this day in 2003! The best way to digest the key lessons from this site is to browse my four volume Best of TaoSecurity Blog book series , published in 2020. It's available in print as seen here, or as a properly formatted HTML-based digital book -- none of that PDF-based fixed format nonsense. Each book is a theme-centric collection of posts with new…

## [We have achieved FreeBSD 15.0-REL with KDE Plasma](https://taosecurity.blogspot.com/2025/11/we-have-achieved-freebsd-150-rel-with.html)

_2025-11-29 · Richard Bejtlich · TaoSecurity Blog_

Houston, we have installed #FreeBSD 15.0-REL with KDE Plasma 6.4.5 on a Lenovo ThinkPad X1 Carbon Gen 6 laptop. I have come full circle. I used to daily drive FreeBSD 5.x on a Thinkpad a20p in the early 2000s. Today I used the "technology preview" method for pkg installation, too. I posted this from the laptop, of course!! Thanks to everyone who made this possible, including the parties who made…

## [Flare-On 12 – Task 8](https://hshrzd.wordpress.com/2025/11/25/flare-on-12-task-8/)

_2025-11-25 · hasherezade · hasherezade&#039;s 1001 nights_

In this mini-series I describe the solutions of my favorite tasks from this year’s Flare-On competition. To those of you who are not familiar, Flare-On is a marathon of reverse engineering. This year it ran for 4 weeks, and consisted Continue reading

## [Flare-On 12 &#8211; Task 9](https://hshrzd.wordpress.com/2025/11/20/flare-on-12-task-9/)

_2025-11-20 · hasherezade · hasherezade&#039;s 1001 nights_

In this mini-series I describe the solutions of my favorite tasks from this year s Flare-On competition. To those of you who are not familiar, Flare-On is a marathon of reverse engineering. This year it ran for 4 weeks, and consisted Continue reading

## [I&#39;m Hosting a New Podcast](https://taosecurity.blogspot.com/2025/11/im-hosting-new-podcast.html)

_2025-11-06 · Richard Bejtlich · TaoSecurity Blog_

I'm hosting a new podcast for Corelight. Check out my first episode with our field CTO, Vince Stoffer. Expect new episodes every two weeks. This is no buddy cop discussion -- max content, minimum banter, in about 15 minutes! https://open.spotify.com/episode/0SD2gUvIuB65YFmjjtXfTR https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362 https://www.youtube.com/watch?v=IgmZxV2OP9k…

## [Creating a Linux Application Using VSCodium, Cline, OpenRouter, and Claude](https://taosecurity.blogspot.com/2025/11/creating-linux-application-using.html)

_2025-11-04 · Richard Bejtlich · TaoSecurity Blog_

In March I created a Windows Application Using Visual Studio Code, Cline, OpenRouter, and Claude . This was a program that created square screen captures. The user doesn't need to manually ensure the dimensions are a square. The program makes the window grow and shrink while keeping the length equal to the height. In June I created an equivalent program on Linux using VSCodium, Cline, OpenRouter,…

## [Stocks ranked by what execs say (Sponsored)](https://crawlproof.com/a/6OPAcvTxMc0a)

_2025-11-04 · **Sponsored**_

Evidence-backed watchlists from earnings calls and filings, cited to real transcripts—not guesses.

## [Company Wrecked by Ransomware Only Spent 120,000 Pounds Per Year on Cyber Security](https://taosecurity.blogspot.com/2025/10/company-wrecked-by-ransomware-only.html)

_2025-10-15 · Richard Bejtlich · TaoSecurity Blog_

Do you remember the story of the UK-based logistics company that closed due to ransomware and laid off 730 workers? Today in an article about a warning to UK businesses about cyber incidents, their “director” said they “were throwing £120,000 a year at \[cyber-security\] with insurance and systems and third-party managed systems.” That’s the cost of one cyber FTE, and it sounds like they didn’t…

## [Stop Shoddy Academic "Research"](https://taosecurity.blogspot.com/2025/10/stop-shoddy-academic-research.html)

_2025-10-02 · Richard Bejtlich · TaoSecurity Blog_

When someone cites one of my works, I get a notice from Research Gate. Today I got one, from an article from the "IEEE Open Journal of the Communications Society." It cited my first book, which is 21 years old. The PDF was available. I noticed the article referenced Prelude, a project I talked about in my first book. This project has been dead for YEARS. If you visit the link for Prelude in the…

## [Creating a Large Text File Viewer by Vibe Coding with Visual Studio Code, Cline, OpenRouter, and Claude 3.7](https://taosecurity.blogspot.com/2025/04/creating-large-text-file-viewer-by-vibe.html)

_2025-04-09 · Richard Bejtlich · TaoSecurity Blog_

I just created another Windows 10/11 application using AI. This is a follow-up to the SquareCap program I posted about a few weeks ago . The problem I was trying to solve this time was opening and searching extremely large text files. I used to use the old Mandiant Highlighter program for this, but it was last updated in 2011 and couldn't handle the 26 GB text file I wanted to open. If you're…

## [Creating a Windows Application Using Visual Studio Code, Cline, OpenRouter, and Claude](https://taosecurity.blogspot.com/2025/03/creating-windows-application-using.html)

_2025-03-25 · Richard Bejtlich · TaoSecurity Blog_

I just created a Windows 10/11 application that takes square screen captures. I did zero coding myself but used Visual Studio Code, Cline, OpenRouter, and Claude. I got the idea by watching a video on so-called Vibe programming by a YouTuber named Memory . I have zero Windows programming experience although I have recently been playing with simple video game development. After creating the…

## [Tutorial: unpacking executables with TinyTracer + PE-sieve](https://hshrzd.wordpress.com/2025/03/22/unpacking-executables-with-tinytracer-pe-sieve/)

_2025-03-22 · hasherezade · hasherezade&#039;s 1001 nights_

Covers: automatic OEP finding, reconstructing IAT, avoiding antidebugs and fixing imports broken by shims In this short blog I would like to demonstrate you how to unpack an executable with PE-sieve and Tiny Tracer. As an example, let s use the Continue reading

## [Process Hollowing on Windows 11 24H2](https://hshrzd.wordpress.com/2025/01/27/process-hollowing-on-windows-11-24h2/)

_2025-01-26 · hasherezade · hasherezade&#039;s 1001 nights_

Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is used in variety of PE loaders, PoCs, and offensive Continue reading

## [Happy 22nd Birthday TaoSecurity Blog](https://taosecurity.blogspot.com/2025/01/happy-22nd-birthday-taosecurity-blog.html)

_2025-01-08 · Richard Bejtlich · TaoSecurity Blog_

Happy birthday TaoSecurity Blog, born on this day in 2003! The best way to digest the key lessons from this site is to browse my four volume Best of TaoSecurity Blog book series , published in 2020. It's available in print as seen here, or as a properly formatted HTML-based digital book -- none of that PDF-based fixed format nonsense. Each book is a theme-centric collection of posts with new…

## [Flare-On 11 &#8211; Task 7](https://hshrzd.wordpress.com/2024/12/09/flare-on-11-task-7/)

_2024-12-09 · hasherezade · hasherezade&#039;s 1001 nights_

Flare-On is an annual CTF challenged by the Mandiant Flare Team. This writeup details approaches to decrypting TCP traffic captured in a PCAP, linked to an AOT-compiled .NET binary. It discusses analyzing the binary, generating FLIRT signatures, and performing cryptanalysis to recover private keys used in Elliptic Curve Cryptography for traffic decryption. Continue reading

## [Flare-On 11 &#8211; Task 5](https://hshrzd.wordpress.com/2024/12/08/flare-on-11-task-5/)

_2024-12-08 · hasherezade · hasherezade&#039;s 1001 nights_

Flare-On is an annual CTF run by Mandiant Flare Team. In this series of writeups I present solutions to some of my favorite tasks from this year. All the sourcecodes are available on my Github, in dedicated repository: flareon2024. The Continue reading

## [Flare-On 11 &#8211; Task 9](https://hshrzd.wordpress.com/2024/10/29/flareon-11-task-9/)

_2024-10-29 · hasherezade · hasherezade&#039;s 1001 nights_

Flare-On is an annual CTF run by Mandiant Flare Team. In this series of writeups I present solutions to some of my favorite tasks from this year. All the sourcecodes are available on my Github, in dedicated repository: flareon2024. The Continue reading

## [Collect Open Source Legends (Sponsored)](https://crawlproof.com/a/tvp8JLiNwV0z)

_2024-10-29 · **Sponsored**_

Open-licensed art, limited foil trading packs, and optional on-chain mints.

## [Flare-On 11 &#8211; Task 10](https://hshrzd.wordpress.com/2024/10/27/flare-on-11-task-10/)

_2024-10-27 · hasherezade · hasherezade&#039;s 1001 nights_

Flare-On is an annual CTF run by Mandiant Flare Team. In this series of writeups I present solutions to some of my favorite tasks from this year. All the sourcecodes are available on my Github, in dedicated repository: flareon2024. The Continue reading

## [What Are Normal Users Supposed to Do with IDS Alerts from Network Gear?](https://taosecurity.blogspot.com/2024/10/what-are-normal-users-supposed-to-do.html)

_2024-10-11 · Richard Bejtlich · TaoSecurity Blog_

Probably once a week, I see posts like this in the r/Ubiquiti subreddit. Ubiquiti makes network gear that includes an "IDS/IPS" feature. I own some older Ubiquiti gear so I am familiar with the product. When you enable this feature, you get alerts like this one, posted by a Redditor: This is everything you get from Ubiquiti. The Redditor is concerned that their system may be trying to compromise…

