Blogs

Technical writeups, research, and insights.

From Vulnerability to Attack Path: Why Findings Need Context
OFFENSIVE SECURITY

From Vulnerability to Attack Path: Why Findings Need Context

A practical insight into how individual vulnerabilities become more meaningful when analyzed as part of an attack path, including exposure, access control, privilege, and business …

Troubleshooting Credentialed Scan Failures
VULNERABILITY ASSESSMENT

Troubleshooting Credentialed Scan Failures

A real world vulnerability assessment case where strict WAF inspection prevented Tenable from completing credentialed …

Detection Coverage Is a Better Security Metric Than Alert Volume
DETECTION ENGINEERING

Detection Coverage Is a Better Security Metric Than Alert Volume

An insight on why detection coverage is a more meaningful security metric than simply counting …

Production Ready Wazuh SIEM Multi Cluster Deployment
DETECTION ENGINEERING

Production Ready Wazuh SIEM Multi Cluster Deployment

A production ready Wazuh 4.14.5 SIEM deployment across 13 VMs, featuring distributed indexers, clustered managers, HAProxy load balancing, …

Showing 1-4 of 4