Blog

Cybersecurity insights, threat hunting guides, and detection engineering articles.

Technical Writeups

Cybersecurity Blog & Case Studies

Deep dives into Wazuh rule tuning, threat hunting queries, Sigma/YARA signatures, and real-world SOC playbook design.

Building Production-Grade Wazuh Detection Rules for Ransomware Behaviors
Detection Engineering
2024-06-15•7 min read

Building Production-Grade Wazuh Detection Rules for Ransomware Behaviors

A deep dive into writing custom XML rules and decoders in Wazuh to detect shadow copy deletion, process injection, and vssadmin abuse in real time.

Proactive Threat Hunting using MITRE ATT&CK & Process Lineage Analysis
Threat Hunting
2024-05-20•10 min read

Proactive Threat Hunting using MITRE ATT&CK & Process Lineage Analysis

Learn how to hunt for stealthy persistence and privilege escalation by inspecting parent-child process anomalies in Microsoft Sysmon and EDR logs.

Threat Hunting
Read Article
Authoring YARA & Sigma Rules to Catch Stealthy Living-off-the-Land Binaries
Detection Engineering
2024-04-10•8 min read

Authoring YARA & Sigma Rules to Catch Stealthy Living-off-the-Land Binaries

Step-by-step methodology for building cross-platform Sigma detection signatures to flag Certutil, Bitsadmin, and Mshta exploitation.

Sigma Rules
Read Article