detection-engineering
Eric Capuano · 14 Sep 2026 · 15 min read
CVE-2026-85706 is being called a path traversal. It contains no traversal sequence at all, which is why detections written from the label match nothing. We built the exploit in a lab and worked out what to anchor on instead.
Read post →
threat-intel
Scott Johnson · 10 Sep 2026 · 27 min read
Five months watching four distinct chains run out of one bulletproof hosting ASN (AS202412 / OMEGATECH LTD). The staging, the persistence and the C2 all varied. The one thing none of them changed was where the lure page came from.
Read post →
threat-hunting
Neeraj Shetty · 09 Sep 2026 · 20 min read
An implant hidden inside the install tree of a real, signed VPN client, where fourteen of the nineteen files are genuine and the launcher is validly signed. Why hash, publisher and certificate hunting all fail against it, and what to hunt instead.
Read post →
threat-intel
Lance McNeese · 08 Sep 2026 · 10 min read
Over eight weeks we watched one email-bombing operator get their domains burned repeatedly and adapt — ending up on free Microsoft 365 tenants that carry no registration record, no WHOIS, and no reputation to score.
Read post →
detection-engineering
Eric Capuano · 26 Aug 2026 · 15 min read
We reproduced a quiet Log4j deserialization bug in the lab. Here are four places a SOC can actually catch it, and one where we decided not to bother.
Read post →
incident-response
Hayden Covington · 18 Aug 2026 · 9 min read
The ActiveSOC responds to an Aur0ra intrusion: email bombing and vishing for access, a disguised Xray-core tunnel for C2, and a custom per-victim locker.
Read post →