Skip to main content
← All Articles

Tag

#Incident Response

50 articles

Advertisement

Evaluating LLMs for SOC Operations and Log Analysis
INFO
Threat Intel

Evaluating LLMs for SOC Operations and Log Analysis

Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Operational Sovereignty: Managing AI Guardrails in SOCs
INFO
Threat Intel

Operational Sovereignty: Managing AI Guardrails in SOCs

Cloud-hosted AI guardrails can hinder SOC investigations, creating a "safety penalty." This article explores reclaiming operational sovereignty.

Runtime Rebel Intel
4 min read · Aug 25, 2026
Augmenting SOCs with Wazuh AI Analyst and LLM Integrations
INFO
Threat Intel

Augmenting SOCs with Wazuh AI Analyst and LLM Integrations

Wazuh integrates AI, including its AI Analyst and LLM options, to augment SOC workflows, reduce analyst fatigue, and accelerate threat detection and response.

Runtime Rebel Intel
4 min read · Aug 21, 2026
Ransom Busters Ransomware Affiliate Poses as Recovery Firm
MEDIUM
Threat Intel

Ransom Busters Ransomware Affiliate Poses as Recovery Firm

A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.

Runtime Rebel Intel
2 min read · Aug 18, 2026
Unit 42: AI Enhances Attack Efficiency, Not Novel TTPs
INFO
Threat Intel

Unit 42: AI Enhances Attack Efficiency, Not Novel TTPs

Unit 42's report reveals AI accelerates attacker operations, shortening attack lifecycles without fundamentally changing TTPs.

Runtime Rebel Intel
4 min read · Aug 8, 2026
Identity Attacks: The Modern SOC's Front Door Challenge
INFO
Identity & Access

Identity Attacks: The Modern SOC's Front Door Challenge

Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.

Runtime Rebel Intel
3 min read · Aug 8, 2026

Advertisement

INFO
Threat Intel

Linux Shell Forensics: Investigating Atuin History in Incident Response

Forensic analysis of Linux shell history using Atuin, a tool that enhances command logging.

Runtime Rebel Intel
5 min read · Aug 7, 2026
Talos Intelligence at Black Hat: Diverse Journeys in Threat Research
INFO
Threat Intel

Talos Intelligence at Black Hat: Diverse Journeys in Threat Research

Talos Intelligence reflects on the diverse career paths of its threat intelligence experts and their presence at Black Hat 2024.

Runtime Rebel Intel
4 min read · Aug 6, 2026
INFO
Threat Intel

zipdump.py: Challenges in Metadata Encoding

An overview of potential issues encountered when handling metadata encoding with zipdump.py, highlighting the need for careful data interpretation.

Runtime Rebel Intel
3 min read · Jul 31, 2026
HIGH
Threat Intel

Post-Exploitation Tactics: Persistence and Lateral Movement Analysis

Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.

Runtime Rebel Intel
4 min read · Jul 30, 2026
INFO
Threat Intel

CISA & ACSC Advise Isolating OT Systems During Cyberattacks

CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.

Runtime Rebel Intel
4 min read · Jul 28, 2026
HIGH
Threat Intel

Nihon Kotsu Cyberattack: System Shutdowns Affect Japan's Largest Taxi Operator

Japan's largest taxi operator, Nihon Kotsu, confirmed a cyberattack forced system shutdowns. This analysis covers the incident's impact and mitigation.

Runtime Rebel Intel
4 min read · Jul 13, 2026
INFO
Threat Intel

Summer IT Coverage Gaps: Mitigating Operational Security Risks

Reduced IT staffing during summer vacations creates security blind spots and increases incident response times.

Runtime Rebel Intel
4 min read · Jul 9, 2026
Securing Events: Integrating Threat Intel & Digital Security
INFO
Threat Intel

Securing Events: Integrating Threat Intel & Digital Security

Event security demands a unified approach to cyber and physical threats. Learn how proactive threat intelligence and robust digital defenses safeguard events.

Runtime Rebel Intel
4 min read · Jul 1, 2026
NDR for Incident Response Teams: Richard Bejtlich on Visibility
INFO
Threat Intel

NDR for Incident Response Teams: Richard Bejtlich on Visibility

Richard Bejtlich explains why NDR is essential for security operations to bridge visibility gaps and move beyond high-volume, low-context alert triage.

Runtime Rebel Intel
3 min read · Jun 25, 2026
94% of Incidents Masked by Anonymized Infrastructure: Attribution Failures
INFO
Threat Intel

94% of Incidents Masked by Anonymized Infrastructure: Attribution Failures

A new survey reveals 94% of cybersecurity incidents leverage anonymized infrastructure, hindering attribution efforts. Security teams struggle despite vast IP data.

Runtime Rebel Intel
4 min read · Jun 16, 2026
MEDIUM
Threat Intel

AI-Enhanced Threats Expose MSP Security Gaps: Integrated Defense

AI-driven attacks are pushing MSP security stacks to their limits. Learn why integrated solutions, automation, and rapid recovery are essential for defending against…

Runtime Rebel Intel
6 min read · Jun 11, 2026
Cybersecurity Stars Awards 2026: Valuing Invisible Security Work
INFO
Threat Intel

Cybersecurity Stars Awards 2026: Valuing Invisible Security Work

The 2026 Cybersecurity Stars Awards highlight critical, often unseen, security efforts. We analyze the impact of recognizing technical excellence.

Runtime Rebel Intel
4 min read · Jun 11, 2026
MEDIUM
Malware

Analyzing Microsoft Access VBA Macros for Malware Detection

Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.

Runtime Rebel Intel
3 min read · May 25, 2026
Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery
MEDIUM
Threat Intel

Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery

Learn how SOC teams can close the visibility gap in phishing detection and use evidence-based analysis to prevent business disruption after a click.

Runtime Rebel Intel
4 min read · May 18, 2026
MEDIUM
Identity & Access

Active Directory Post-Breach Persistence: Why Password Resets Fail

Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.

Runtime Rebel Intel
4 min read · May 11, 2026
MEDIUM
Threat Intel

Canvas LMS Cyberattack: Thousands of Schools Face Service Disruption

Canvas LMS restores services after a significant cyberattack disrupted online learning for thousands of students globally during critical exam periods.

Runtime Rebel Intel
3 min read · May 11, 2026
Neutralizing Patient Zero: Strategies to Prevent Stealth Breaches
HIGH
Threat Intel

Neutralizing Patient Zero: Strategies to Prevent Stealth Breaches

Analyze how AI-driven social engineering creates a Patient Zero scenario and explore technical strategies to contain stealth breaches before total shutdown.

Runtime Rebel Intel
4 min read · May 7, 2026
Day Zero Readiness: Bridging Incident Response Operational Gaps
INFO
Threat Intel

Day Zero Readiness: Bridging Incident Response Operational Gaps

Identify and close the operational gaps in incident response that hinder day-zero readiness, ensuring external partners can act immediately during a breach.

Runtime Rebel Intel
3 min read · May 7, 2026