Default Author Image

The Human Element: Turning Threat Actor OPSEC Fails into Investigative Breakthroughs

In this post, we explore how the psychological traps of operational security can unmask even the most sophisticated actors. The post The Human Element: Turning Threat Actor OPSEC Fails into Investigative Breakthroughs ...
Modern SecOps: What an AI-ready SOC actually means with Anton Chuvakin

Beyond “Is Your SOC AI Ready?” Plan the Journey!

You read the “AI-ready SOC pillars” blog, but you still see a lot of this:Bungled AI SOC transitionHow do we do better?Let’s go through all 5 pillars aka readiness dimensions and see what we ...
No, I still won’t accept your LinkedIn invitation.

No, I still won’t accept your LinkedIn invitation.

I made the above statement on LinkedIn once my invitation queue hit 40, and you could say it went a bit viral. That wasn’t surprising, but what was surprising was the reaction ...
SOC Visibility Triad is Now A Quad — SOC Visibility Quad 2025

SOC Visibility Triad is Now A Quad — SOC Visibility Quad 2025

SOC Visibility Triad is Now A Quad — SOC Visibility Quad 2025I will be really, really honest with you — I have been totally “writer-blocked” (more “analyst blocked”, really) and I decided to release it anyway today … ...
“Maverick” — Scorched Earth SIEM Migration FTW!

“Maverick” — Scorched Earth SIEM Migration FTW!

| | opsec, SIEM
“Maverick” — Scorched Earth SIEM Migration FTW!In my days there, Gartner had Maverick research (here is mine, from 2015 about social engineering AIs…. yes, really!) that “deliberately exposed unconventional thinking and may not agree ...
Output-driven SIEM — 13 years later

Output-driven SIEM — 13 years later

Output-driven SIEM — 13 years laterOutput-driven SIEM! Apart from EDR and SOC visibility triad, this is probably my most known “invention” even though I was very clear that I stole this from the Vigilant crew ...
JFK and the Houthis: Haste Makes Waste of Security 

JFK and the Houthis: Haste Makes Waste of Security 

Rather than simply exposing buried truths of the assassination, the final tranche of JFK files also exposed the personal information, including social security numbers, of a parade of people associated with the ...
Security Boulevard
Don’t Touch That Object! Finding SACL Tripwires During Red Team Ops

Don’t Touch That Object! Finding SACL Tripwires During Red Team Ops

During red team operations, stealth is a critical component. We spend a great deal of time ensuring our payloads will evade any endpoint detection and response (EDR) solution, our traffic is obfuscated ...
OpSec manager on computer

Cyber Lingo: OpSec meaning & uses

The post Cyber Lingo: OpSec meaning & uses appeared first on Click Armor ...