Latest Articles
Finding hooks with windbg
Uncategorized
In this blogpost we are going to look into hooks, how to find them, and how to restore the original…
Visualizing MISP Threat Intelligence in Power BI – An NVISO TI Tutorial
Blue Team
In this blog we will explain how to use the functionality of Power BI to visualize your MISP data in…
Cortex XSOAR Tips & Tricks – Leveraging dynamic sections – text
SOC
Introduction Cortex XSOAR is a security oriented automation platform, and one of the areas where it stands out is customization.…
Cortex XSOAR Tips & Tricks – Leveraging dynamic sections – number widgets
Blue Team
Introduction Cortex XSOAR is a security oriented automation platform, and one of the areas where it stands out is customization.…
Cortex XSOAR Tips & Tricks – Dealing with dates
SOC
Introduction As an automation platform, Cortex XSOAR fetches data that represents events set at defined moments in time. That metadata…
DeTT&CT: Automate your detection coverage with dettectinator
Detection Engineering
Introduction Last year, I published an article on mapping detection to the MITRE ATT&CK framework using DeTT&CT. In the article,…
Top things that you might not be doing (yet) in Entra Conditional Access
Microsoft 365
Introduction In this blog post, I focus on the top things that you might not be doing (yet) in Entra…
Scaling your threat hunting operations with CrowdStrike and PSFalcon
PowerShell
Introduction Most modern day EDRs have some sort of feature which allows blue teamers to remotely connect to hosts with…
A Beginner’s Guide to Adversary Emulation with Caldera
Adversary Emulation
Target Audience The target audience for this blog post is individuals who have a basic understanding of cybersecurity concepts and…
The dangers of trust policies in AWS
AWS
Introduction Everyone that has used Amazon Web Services (AWS) knows that the cloud environment has a unique way of granting…
