Blog
Threat hunting and detection engineering, written down: the reporting behind rules, the telemetry that feeds them, and the gaps that get attackers through.
5 articles
Vulnerabilities & ExploitsWhat is vulnerability management?
About 6% of published CVEs are ever exploited in the wild. A scanner reports the other 94% with the same red badge. That gap is the entire job. Buying a scanner takes an afternoon. Running a…
2026-07-31 · 11 min read
Vulnerabilities & ExploitsWhat Is a Zero-Day Vulnerability?
An operator wrote human2.aspx into C:\MOVEitTransfer\wwwroot\ four days before Progress had a patch to give anyone. CISA's KEV entry for the bug behind it lists CWE-89. SQL injection, the same class…
2026-07-31 · 8 min read
Vulnerabilities & ExploitsWhat Is Exploit Chaining?
One request, no credentials, and the appliance runs whatever sits inside the ${}. GET…
2026-07-31 · 7 min read
Vulnerabilities & ExploitsWhat is CVSS and why severity is not risk
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H scores 10.0. That string is the Base vector Palo Alto Networks published for CVE-2024-3400. It says nothing about whether the…
2026-07-31 · 9 min read
Vulnerabilities & ExploitsWhat is a CVE? What the record does not say
The entire NVD description for CVE-2023-23397 is six words: "Microsoft Outlook Elevation of Privilege Vulnerability." That record carries a 9.8 CVSS base score and entered CISA's KEV catalog on 14…
2026-07-31 · 10 min read