Writing detections when stuck with EDR
Securing your estate: The First Step
Introduction A commonly forgotten fact within the cybersecurity industry is that most organizations are not equipped nor have started to form any sort of security program. This is the case for many reasons because most organizations are SMBs so they …
Subscribe to:
Posts (Atom)
Featured
Goblin Diary #2 - AI Tools for Analysts 🐯
Dont Use AI Analyst work is built on the human capacity for creativity, memory recall and information gathering and using so called 'AI...
Popular
-
Introduction Tired of watching you and your friends get compromised, do exactly what's in this blog and start beating adversaries. Avoid...
-
Introduction This document details how an analyst should conduct investigations and triage in the normal duties of their job. It will des...
-
Introduction This blog series will capture how to maximise the protection of an endpoint using the various technologies in the Defender su...
-
Introduction Now that I have covered the advanced features obtained from Defender for Cloud and the complexities of Defender for Endpoint wi...
-
Introduction Continuing on from my last post that captured using Defender for Cloud to gain powerful additional features on top of defender...
-
Analysis In this post, I explain analysis and the associated techniques to mean at the lowest possible level a human’s ability to consume ...
-
Introductions How you as an analyst handle true positives is life and death in the eyes of potential victims. Traditionally the industry ele...
-
Introduction Making the leap to purchasing and maintaining an EDR solution can be huge for organisations so huge in fact that they never rea...
-
❗take the time to read the bottom of this page. Introduction Proxmox is a virtualisation technology stack that is quickly becoming the...
-
Introduction This post outlines a format for note-taking designed to aid analysts and ensure the knowledge they acquire over time is kep...