detection 36
- Less panic patching, more precision
- Grading on a curve: How to assess a pentest
- From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents
- Investigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agents
- Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
- How to detect HTTP/2 abuse in Apache web server logs
- Remove SPNs and Fix Kerberoasting
- Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
- Investigating server compromises with cgroups: A Linux DFIR primer
- Nuclei Templates - April 2026
- State-sponsored actors, better known as the friends you don’t want
- Slamming the Door on Quick Assist Tech Support Scams and Abuse
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
- Hunting ClickFix Win + X Variants
- Open-Sourcing 140+ Weaponisable File Type Samples: Test What Your Defences Actually Block
- Insights into the clustering and reuse of phone numbers in scam emails
- The Defensive Stack is Exposed: LLMs, Reverse Engineering, and the End of Opaque Defense
- AWS Security Digest #259 - Better late
- Tuned by Design: Why Detection Engineering Needs Its Own Development Lifecycle
- Essential Data Sources for Detection Beyond the Endpoint
- The Life-Dinner Principle in Detection
- Identifying and containing a data breach
- Detection Visibility Metrics
- Spotting CI/CD misconfigurations before the bots do: Securing GitHub Actions with Datadog IaC Security
- Identity, browsers, and node.js: Everything you missed in the Threat Detection Report miniseries
- Detect runtime threats in Python Lambda functions with Datadog AAP
- Validating Browser Defences with Push Security and delivr.to
- From the field to the report and back again: How incident responders can use the Year in Review
- The threat hunter’s gambit
- CI/CD security: How to secure your GitHub ecosystem
- CI/CD security: threat modeling using a MITRE-style threat matrix
- AI in cybersecurity: The good, the bad, and the FUD
- Year in Review: Vulnerabilities old and new and something React2
- PrivEsc: Abusing the Service Control Manager for Stealthy & Persistent LPE
- Introducing MacNoise!
- Building a Detection Foundation: Part 5 - Correlation in Practice