Advertisement
Evaluating LLMs for SOC Operations and Log Analysis
Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.
Operational Sovereignty: Managing AI Guardrails in SOCs
Cloud-hosted AI guardrails can hinder SOC investigations, creating a "safety penalty." This article explores reclaiming operational sovereignty.
Augmenting SOCs with Wazuh AI Analyst and LLM Integrations
Wazuh integrates AI, including its AI Analyst and LLM options, to augment SOC workflows, reduce analyst fatigue, and accelerate threat detection and response.
Ransom Busters Ransomware Affiliate Poses as Recovery Firm
A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.
Unit 42: AI Enhances Attack Efficiency, Not Novel TTPs
Unit 42's report reveals AI accelerates attacker operations, shortening attack lifecycles without fundamentally changing TTPs.
Identity Attacks: The Modern SOC's Front Door Challenge
Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.
Advertisement
Linux Shell Forensics: Investigating Atuin History in Incident Response
Forensic analysis of Linux shell history using Atuin, a tool that enhances command logging.
Talos Intelligence at Black Hat: Diverse Journeys in Threat Research
Talos Intelligence reflects on the diverse career paths of its threat intelligence experts and their presence at Black Hat 2024.
zipdump.py: Challenges in Metadata Encoding
An overview of potential issues encountered when handling metadata encoding with zipdump.py, highlighting the need for careful data interpretation.
Post-Exploitation Tactics: Persistence and Lateral Movement Analysis
Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.
CISA & ACSC Advise Isolating OT Systems During Cyberattacks
CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.
Nihon Kotsu Cyberattack: System Shutdowns Affect Japan's Largest Taxi Operator
Japan's largest taxi operator, Nihon Kotsu, confirmed a cyberattack forced system shutdowns. This analysis covers the incident's impact and mitigation.
Summer IT Coverage Gaps: Mitigating Operational Security Risks
Reduced IT staffing during summer vacations creates security blind spots and increases incident response times.
Securing Events: Integrating Threat Intel & Digital Security
Event security demands a unified approach to cyber and physical threats. Learn how proactive threat intelligence and robust digital defenses safeguard events.
NDR for Incident Response Teams: Richard Bejtlich on Visibility
Richard Bejtlich explains why NDR is essential for security operations to bridge visibility gaps and move beyond high-volume, low-context alert triage.
94% of Incidents Masked by Anonymized Infrastructure: Attribution Failures
A new survey reveals 94% of cybersecurity incidents leverage anonymized infrastructure, hindering attribution efforts. Security teams struggle despite vast IP data.
AI-Enhanced Threats Expose MSP Security Gaps: Integrated Defense
AI-driven attacks are pushing MSP security stacks to their limits. Learn why integrated solutions, automation, and rapid recovery are essential for defending against…
Cybersecurity Stars Awards 2026: Valuing Invisible Security Work
The 2026 Cybersecurity Stars Awards highlight critical, often unseen, security efforts. We analyze the impact of recognizing technical excellence.
Analyzing Microsoft Access VBA Macros for Malware Detection
Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.
Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery
Learn how SOC teams can close the visibility gap in phishing detection and use evidence-based analysis to prevent business disruption after a click.
Active Directory Post-Breach Persistence: Why Password Resets Fail
Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.
Canvas LMS Cyberattack: Thousands of Schools Face Service Disruption
Canvas LMS restores services after a significant cyberattack disrupted online learning for thousands of students globally during critical exam periods.
Neutralizing Patient Zero: Strategies to Prevent Stealth Breaches
Analyze how AI-driven social engineering creates a Patient Zero scenario and explore technical strategies to contain stealth breaches before total shutdown.
Day Zero Readiness: Bridging Incident Response Operational Gaps
Identify and close the operational gaps in incident response that hinder day-zero readiness, ensuring external partners can act immediately during a breach.