Ideas from the research and operations teams.
Explore published topics across security operations, threat research and delivery models.
Publication dates describe the original articles. These topic overviews retain their historical context.
Interaction-hooked phishing
Research on credential theft through Windows UIAutomation, without a phishing email or link.
How agentic AI reshapes security operations
An examination of SOC overload and turning telemetry into useful investigation context.
Human and AI collaboration in threat hunting
AI helps defenders find anomalies while helping attackers conceal activity.
SOC, SOCaaS and MDR: choosing an operating model
Security delivery should fit an organization’s attack surface, resources and environment.
MDR architecture: a coordinated operation
A look at the response pressure created by rapid attacker movement.
MDR detection rules beyond endpoint alerts
A fake CAPTCHA and Lumma Stealer example shows why endpoint silence needs further investigation.
Visibility beyond EDR
Custom detections and integrated playbooks address activity that endpoint tools may miss.
Follow the next chapter.
Request security research, platform news and partner updates.
