Blog
Threat hunting and detection engineering, written down: the reporting behind rules, the telemetry that feeds them, and the gaps that get attackers through.
6 articles
Incident ResponseWhat Is a Lessons Learned Session in IR?
Two lines came out of the same incident. The first: "improve communication with the network team." The second: "on-call had no out-of-hours route to network engineering, so the rota now lists a named…
2026-07-31 · 8 min read
Incident ResponseWhat Is Post-Incident Review (PIR)?
NIST SP 800-61 Revision 2 lists nine questions for a lessons learned meeting. The last three are the only ones that point forward, and they are the ones teams skip. Corrective actions, precursors and…
2026-07-31 · 10 min read
Incident ResponseWhat Is Root Cause Analysis in Security Incidents?
At 09:14 a user typed their password into a page that looked like the corporate SSO portal. By 10:47, 4,214 files had been read from \\FS01\Finance. The report that names the phishing email as the…
2026-07-31 · 9 min read
Incident ResponseWhat Is an Incident Timeline in DFIR?
MFTECmd writes a column named SI<FN into its $MFT CSV. It holds a boolean. True means the $STANDARD_INFORMATION created time on that file is earlier than the $FILE_NAME created time, which on a file…
2026-07-31 · 10 min read
Incident ResponseWhat is an incident response plan?
Article 33 of the GDPR gives a controller 72 hours from becoming aware of a personal data breach to notify the supervisory authority. Not 72 hours from containment. Not 72 hours from the forensic…
2026-07-31 · 10 min read
Incident ResponseWhat Is Incident Response?
NIST SP 800-61 Revision 3 shipped in April 2025 and removed the four-phase incident response lifecycle that everyone quotes. The phases did not stop being true. NIST decided the details of how to run…
2026-07-31 · 10 min read