Blog

Technical articles on cybersecurity, detection and compliance. By field experts.

Threat insightsPhobosRansomwareSigmaDetection EngineeringShadow Copies

Detecting Phobos: What a Ransomware Actually Does, and the Rule That Stops It

We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.

Threat insightsBotnet / LoaderEmotetThreat DetectionYARA

Emotet Botnet Resurfaces: ThreatClaw Adds YARA Detection for SMBs

Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.

Threat insightsDrokbkRemote Access TrojanThreat DetectionYARA

Drokbk RAT Detection: ThreatClaw Adds Coverage for Stealthy Malware

Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.

Threat insightsDosiaMalwareThreat DetectionYARA

Dosia Malware Detection: ThreatClaw Adds YARA Rules for SMBs

Dosia malware targets SMBs with obfuscation and tool transfer tactics. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this threat effectively.

Threat insightsThreat IntelDetection

MacSync Stealer: Malvertising Lures SMBs into macOS Threats

Fake AI install guides via malvertising deliver MacSync Stealer. Learn ATT&CK techniques and SMB detection/response strategies for macOS threats.

Threat insightsDarkgateLoaderThreat DetectionYARA

Darkgate Loader Threat Detection: ThreatClaw Adds YARA Coverage

Darkgate, a sophisticated malware loader, evades defenses with obfuscation and process injection. Learn how ThreatClaw’s new YARA rules help SMBs and MSSPs detect this threat.

Threat insightsCryptolockerRansomwareThreat DetectionYARA

Cryptolocker Ransomware: Detection Now in ThreatClaw for SMBs & MSSPs

ThreatClaw adds YARA-based detection for Cryptolocker ransomware. Learn how this threat encrypts data, disrupts recovery, and why SMBs/MSSPs must act now.

Threat insightsShadow AIDetection EngineeringSigmaLLM Security

Detecting Shadow AI: Finding Unsanctioned AI Use in Your Logs

Shadow AI is shadow IT's faster, leakier cousin. This guide covers what it is, why it is a real risk, and — the part nobody writes about — how to actually detect unsanctioned AI use in your network, proxy and endpoint logs, with a working Sigma rule.

Threat insightsValid AccountsInsider ThreatThreat DetectionSigma

The DGFiP Breach: An Attack No Antivirus Could Ever Flag

Valid credentials, internal VPN, business application: the French tax authority breach shows why behavioural detection beats signatures every time.

Threat insightsSIEMWazuhOpen SourceSigma

Open Source SIEM in 2026: An Honest Comparison of Wazuh, Elastic, Security Onion and Graylog

Wazuh, Elastic/Security Onion, Graylog, OpenSearch — a genuinely balanced comparison of free and open-source SIEM options for SMBs, with real resource requirements, a Sigma-ingestion table, and the part every vendor page skips: what happens after install day.

Threat insightsOWASPLLM SecurityPrompt InjectionAI Red Teaming

OWASP Top 10 for LLM Applications: A Practical Testing Reference

The full OWASP Top 10 for LLM Applications (2025 edition), explained the way most write-ups skip: for each of the 10 risks, what it is, a concrete example, and — the part that matters — how you actually test or detect it.

Threat insightsCryptbotInfostealerThreat DetectionYARA

Cryptbot Infostealer Detection: ThreatClaw Enhances SMB Protection

Cryptbot infostealer targets credentials and session data. Learn how ThreatClaw’s new YARA rules help MSSPs and SMBs detect and mitigate this persistent threat.

Threat insightsCosmicdukeTargeted ImplantThreat DetectionYARA

Cosmicduke Malware Detection: ThreatClaw Adds YARA Rules for Targeted Implant

ThreatClaw now detects Cosmicduke, a stealthy targeted implant. Learn how this malware operates, its MITRE ATT&CK techniques, and why SMBs/MSSPs must stay vigilant.

Product updatesKEVDétection

New ThreatClaw Detections: Exploited CVEs in VMware, SharePoint & MLflow

This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.

Threat insightsContiRansomwareThreat DetectionYARA

Conti Ransomware: Detection Coverage & Why SMBs Must Act Now

Conti ransomware remains a top threat to SMBs. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it with zero false positives.

Threat insightsCobaltCommand-And-Control FrameworkThreat DetectionYARA

Cobalt C2 Framework Detection: ThreatClaw Adds YARA Coverage

ThreatClaw now detects Cobalt, a sophisticated command-and-control framework. Learn how this threat operates and why SMBs/MSSPs must defend against it.

Threat insightsCloudeyeLoaderThreat DetectionYARA

Cloudeye Loader Detection: ThreatClaw Shields SMBs from Stealthy Malware

Cloudeye, a sophisticated malware loader, evades defenses with obfuscation and process injection. ThreatClaw now delivers YARA-based detection to protect SMBs and MSSPs.

Threat insightsThreat IntelDetection

SMBs on Alert: Three Actively Exploited Vulnerabilities Demand Action

CISA adds three critical vulnerabilities to its KEV catalog. Learn the MITRE ATT&CK techniques, detection strategies, and how SMBs can respond effectively.

Threat insightsBlankgrabberInfostealerThreat DetectionYARA

Blankgrabber Infostealer: Detection Now Live in ThreatClaw Feeds

Blankgrabber infostealer targets credentials and session data. Learn how this malware operates and why ThreatClaw’s YARA rules now detect it for SMBs and MSSPs.

Product updatesNIS2ReCyFComplianceOSCAL

Your detection rules, mapped to NIS2 and ReCyF

Every ThreatClaw feed subscription now ships with a per-requirement coverage map for NIS2 and ReCyF, an OSCAL export, and a connector that pre-fills your GRC. Here is exactly how it works, and what it does not claim.

Threat insightsBkransomwareRansomwareThreat DetectionYARA

Bkransomware Detection: ThreatClaw Adds YARA Rules for SMBs

Bkransomware targets SMBs with encryption and recovery disruption. ThreatClaw now ships 39 validated YARA rules to detect this emerging ransomware threat.

Threat insightsBanking TrojanBeatbankerThreat DetectionYARA

Beatbanker Banking Trojan: Detection Now in ThreatClaw Feeds

Beatbanker is a stealthy banking trojan targeting financial data. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it for SMBs and MSSPs.

Threat insightsBanbraBanking TrojanThreat DetectionYARA

Banbra Banking Trojan: Detection Now Live in ThreatClaw Feeds

Banbra banking trojan targets financial data via input capture and local system exfiltration. Learn how ThreatClaw now detects this threat for SMBs and MSSPs.

Product updatesT1003.002T1003.004KEVDétection

New ThreatClaw Detections: Linux & Windows Persistence, 4 Exploited CVEs

This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.

Threat insightsAvoslockerRansomwareThreat DetectionYARA

Avoslocker Ransomware: Detection Coverage for SMBs and MSSPs

Avoslocker ransomware targets SMBs with encryption and recovery disruption. Learn how ThreatClaw’s YARA rules now detect this threat to protect clients.

Threat insightsAspxspyMalwareThreat DetectionYARA

Aspxspy Malware Detection: ThreatClaw Adds Coverage for Stealthy Web Shell

Aspxspy malware targets SMBs via obfuscated web shells. Learn how it operates, why it evades defenses, and how ThreatClaw now detects it with zero false positives.

Threat insightsAmadeyLoaderThreat DetectionYARA

Amadey Loader Detection: ThreatClaw Adds YARA Rules for SMBs & MSSPs

Amadey loader resurfaces as a persistent threat. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw’s new YARA rules help SMBs and MSSPs detect it.

Threat insightsThreat IntelDetection

Progress LoadMaster Flaw Exploited: SMBs Must Act Now

CISA warns of active exploitation of a Progress LoadMaster command injection flaw. Learn ATT&CK techniques and SMB detection/response steps.

Threat insightsAkiraRansomwareThreat DetectionYARA

Akira Ransomware: Detection Coverage & Why SMBs Must Act Now

Akira ransomware targets SMBs with double-extortion tactics. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it.

Product updatesReleaseYARARansomwareThreat Detection

New Coverage: 51 Fresh Malware Families in the ThreatClaw YARA Feed

The August rule release adds 51 new malware families to the YARA feed, forged from live in-the-wild samples, every rule compile-validated on the real engine with zero false positives on a benign corpus.

Threat insightsSigmaYARADetectionPlaybookCACAOATT&CKThreat IntelligenceRule Feed

Proven Detection, Not Scraped Rules: What Sets the ThreatClaw Feed Apart

A rule feed is not worth its rule count. It is worth the proof that the rules fire and what you do when they trigger. Tested on real engines, false-positive-proven, signed, and every rule ships an investigation playbook wired to our other engines.

Product updatesYARADetectionPrometeiWannaCryEternalBlueSpyNoteGhostNFCRansomwareAndroidLinuxThreat Intelligence

YARA Summer Pack: 72 malware families covered this summer (Prometei, WannaCry, SpyNote…)

From June to August 2026, ThreatClaw forged 72 new malware families into its YARA feed: Prometei, WannaCry, EternalBlue, GhostNFC, SpyNote, Mamont, Neshta… each tested against 5,694 legitimate binaries, zero false positives.

Threat insightsThreat IntelDetection

Hard-Coded Passwords in Firewalls: SMBs Must Act Now

CVE-2026-20316 exposes Cisco Secure Firewall Management Center via hard-coded credentials. Learn ATT&CK techniques and SMB detection steps.

Threat insightsThreat IntelDetection

Zimbra Zero-Day Exploit: How SMBs Can Detect Email Theft Threats

A new Zimbra zero-day exploit enables email theft via phishing. Learn the MITRE ATT&CK techniques and how SMBs can detect and respond.

Product updatesT1566.002KEVDétection

New Detection: Brand Spoofing Surge & 6 Exploited CVEs in SMB

ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.

Threat insightsSigmaNucleiCVESharePointDetection

SharePoint CVE-2026-45659: The Deserialization That Leads to Warlock Ransomware

Deserialization of untrusted data yields RCE on on-premise SharePoint. In the KEV, exploited by Storm-2603. Here is the Sigma rule on w3wp and Nuclei detection.

Threat insightsIOCThreat intelSMBVulnerabilities

DBIR 2026: 96% of Ransomware Victims Are SMBs, Now What?

The Verizon 2026 report puts vulnerability exploitation ahead as the top initial access vector and confirms ransomware mainly hits SMBs. The concrete actions.

Product updatesYARADetectionPrometeiLinux BotnetThreat Intelligence

14 new malware families covered: the June YARA batch

Prometei botnet on Linux, Windows code injection, Office macros, Android, downloaders. ThreatClaw adds 14 fresh malware families to its YARA feed, 391 rules, tested against 5,694 legitimate binaries with zero false positives.

Threat insightsNucleiCVEVPNPAN-OSDetection

PAN-OS GlobalProtect CVE-2026-0257: The Cookie That Is Not Verified

A poorly validated override cookie opens an unauthorized GlobalProtect session. Score raised to 7.8, in the KEV, exploited. Nuclei detection and mitigation.

Threat insightsNucleiCVEMSPSupply chainDetection

SimpleHelp CVE-2026-48558: When Your MSP Becomes the Way In

An unsigned OIDC token grants technician access to SimpleHelp RMM. CVSS 10, in the KEV, exploited to deliver stealers. Nuclei detection and accounts to watch.

Threat insightsVelociraptorDFIRThreat huntingDetectionIncident response

Hunting an Edge Appliance Compromise with Velociraptor

After a VPN or firewall intrusion, the appliance service account pivots into AD. Here is how to hunt those traces across the whole estate with Velociraptor.

Threat insightsLLMRed teamPrompt injectionAIApplication security

When a Prompt Opens a Shell: RCE via Injection in AI Agents

Microsoft showed a single prompt can launch calc.exe via Semantic Kernel. CVE-2026-26030 and 25592 turn injection into RCE. How to test your own AI agents.

Threat insightsSigmaOAuthSaaSIdentityDetection

ShinyHunters: The OAuth Abuse That Bypasses MFA on Salesforce and M365

ShinyHunters hijacks trusted OAuth connections to exfiltrate CRM data without ever triggering MFA. Here is how to detect abusive consents and tokens.

Threat insightsSigmaYARARansomwareBYOVDDetection

The Gentlemen: The RaaS That Enters at the Edge and Neutralizes EDR

The Gentlemen gets in via compromised FortiGates, disables EDR with a vulnerable driver (BYOVD) and enumerates AD. Here are the Sigma and YARA rules to spot it.

Threat insightsSuricataCVEVPNRansomwareDetection

Check Point VPN: The Client Dictates Authentication (CVE-2026-50751)

One byte of the IKEv1 Vendor ID disables server-side verification. Exploited since May by a Qilin affiliate. Here are the IOCs, the Suricata rule, and the fix.

Threat insightsWAFCVECitrixRansomwareDetection

Citrix NetScaler: CitrixBleed Strikes Again (CVE-2026-8451), the WAF as Shield

A NetScaler memory leak in SAML IdP mode replays the CitrixBleed scenario: token theft, MFA bypass, DragonForce. Here is WAF virtual patching.

Threat insightsThreat intelDétection

SQL Injection to Persistence: How SMBs Can Detect Post-Compromise Threats

Threat actors exploit SQL injection to gain access, then modify environments for persistence. Learn ATT&CK techniques and SMB detection strategies.

Threat insightsFalcoKubernetesCloudDetectionOPA

Kubernetes Container Escape to Cloud Pivot: Detect at Runtime

Google observes clusters attacked within 18 minutes and escapes via privileged pods. Here is runtime detection with Falco and admission guardrails with OPA.

Threat insightsSigmaQuick AssistRansomwareDetectionSocial engineering

Payouts King: The Fake Teams Support That Installs Edgecution via Quick Assist

Fake IT support on Teams pushes the victim to open Quick Assist, then installs Edgecution, an Edge extension that escapes the sandbox. The Sigma detection.

Threat insightsNucleiCVESonicWallDetectionKEV

SonicWall SMA1000: Two Zero-Days Exploited, How to Detect and Prioritize

CVE-2026-15409 (SSRF, CVSS 10) and CVE-2026-15410 (root RCE) hit SMA1000 appliances. In the KEV catalog. Here are the fixed versions, IOCs, and Nuclei detection.

Threat insightsSigmaEntra IDIdentityDetectionPhishing

Entra ID: The Fake Passkey Enrollment That Buys Durable Persistence

Via vishing, actor O-UNC-066 registers its own FIDO2 passkey in the victim's account. Detect the method addition correlated with a risky sign-in.

Threat insightsDetectionFeedsSIEMDetection Engineering

How to Evaluate a Detection Rule Feed: A Buyer's Checklist

Rule count is a vanity metric. Here is the checklist that actually decides whether a Sigma, YARA or NIDS detection feed is worth paying for: license for resale, deduplication, conversion coverage, false-positive discipline, signature and maintenance cadence.

Threat insightsIOCThreat IntelligenceFeedsMISP

IOC Feeds Compared: abuse.ch, OTX, MISP and Curated Aggregation

The best IOC feeds are largely free. So what do you actually pay for? A practical comparison of abuse.ch, AlienVault OTX, MISP and commercial threat intel, and where a curated aggregation layer earns its place.

Threat insightsYARASupply chainnpmDetectionDevSecOps

npm: --ignore-scripts No Longer Enough, the Payload Fires at Import

The @asyncapi package compromise runs its payload at module load, not at install. Why --ignore-scripts fails and how to detect it with YARA.

Threat insightsNucleiVulnerability ScanningFeedsKEV

Nuclei Template Feeds: Community Templates, the Volume Problem, and KEV/EPSS Prioritization

How to prioritize Nuclei templates: cut by severity, fingerprint the stack, then rank by CISA KEV and EPSS so you scan what is actually exploited first. A concrete workflow, plus where a curated feed saves the work.

Threat insightsSigmaDetectionSIEMFeeds

Sigma Rule Feeds Compared: SigmaHQ, SOC Prime, Valhalla and Curated Alternatives

SigmaHQ is free, so why pay for a Sigma rule feed? A practical comparison of the public corpus, SOC Prime, Nextron Valhalla and curated feeds, with the criteria that actually matter for a SOC or MSSP.

Threat insightsSuricataNIDSNetworkFeeds

Suricata and NIDS Rulesets Compared: ET Open, ET Pro and Curated Alternatives

ET Open is free, ET Pro and Talos are paid, and curated feeds sit in between. A practical comparison of Suricata and Snort rulesets for network detection, with the criteria that matter for a SOC or MSSP.

Threat insightsYARAMalwareDFIRFeeds

YARA Rule Feeds Compared: Valhalla, Open Sources and When a Curated Feed Pays Off

Nextron Valhalla is the reference YARA feed, and there are strong free sources too. A practical comparison for EDR, DFIR and threat hunting, with the criteria that decide whether a curated YARA feed is worth paying for.

Threat insightsSigmaClickFixDetectionRansomwareSMB

ClickFix: From Fake CAPTCHA to Ransomware, a Reusable Sigma RunMRU Rule

ClickFix tricks users into pasting a PowerShell command via Win+R. Detect it through the RunMRU key and encoded arguments, before ACR Stealer or Interlock lands.

Threat insightsIOCPhishingRansomwareSMBDetection

Fake Interpol Emails: The Ransomware Aimed Straight at SMBs

A campaign impersonates Interpol to trap SMBs: Proton Drive link, encrypted archive, executable disguised as a video. The indicators and the detection rule.

Threat insightsYARASupply chainnpmRustDetection

IronWorm: A Rust-Built npm Worm That Steals Your Cloud and AI Keys

IronWorm hides a Rust binary triggered at preinstall, harvests cloud and AI keys, then self-propagates via GitHub. Here is the YARA rule to detect it.

Product updatesKEVDétection

New ThreatClaw Coverage: Exploited CVEs in SharePoint, Fortinet & Oracle

This week, ThreatClaw expands detection for 12 newly exploited CVEs, including critical flaws in Microsoft SharePoint, Fortinet FortiSandbox, and Oracle E-Business Suite.

Threat insightsAI AgentsRansomwareThreat Detection

JADEPUFFER: Detecting the First Autonomous AI-Agent Ransomware

AI agent ransomware detection: how JADEPUFFER encrypted victims without a human operator, and the correlation method that catches it without false positives.

Threat insightsOPA RegoHuman-in-the-LoopRemediation

Keeping Humans in the Loop: Rego Approval Gates Before AI Agent Remediation

An OPA Rego policy enforces mandatory human approval before AI agent remediation runs: automatic isolation, sign-off required for any destructive action.

Threat insightsWAFSEOBotsOWASP CRS

Blocking AI Scraper Bots (GPTBot, LLM Crawlers) Without Breaking Your SEO: OWASP CRS WAF Rules

GPTBot, ClaudeBot and Bytespider eat your bandwidth and content. How to block them with WAF rules, without touching Googlebot or hurting your search rankings.

Threat insightsLLM SecurityRed TeamAI Act

Garak vs PyRIT vs Promptfoo: Choosing Your LLM Red Team Tools

A comparison of LLM red team tools: Garak scans the raw model, PyRIT runs multi-turn attacks, and Promptfoo tests the application in CI/CD before production.

Threat insightsSigmaInfostealerLOLBinsDetectionPowerShell

VEIL#DROP: A PowerShell Loader Hidden Behind Blogger Pages

VEIL#DROP delivers PureLogs in memory via a fake PDF JavaScript and trusted Blogspot pages. Here is the chain, the fallback LOLBins, and Sigma detection.

Threat insightsComplianceNIS2RegulationSigma

NIS2: France Before the CJEU, What the Deadline Changes for Companies

The Commission referred France to the CJEU on July 8, 2026 for failing to transpose NIS2. Penalties loom and the resilience law is delayed: what to anticipate.

Threat insightsRed TeamMCPPrompt Injection

Red-Teaming an MCP Server: Testing Indirect Prompt Injection to Tool Execution

How to red-team an MCP server against indirect prompt injection: verify a poisoned document cannot reach a tool call, file access, or command execution.

Threat insightsNucleiShadow AIExposure

Shadow AI: Scanning Exposed Self-Hosted AI Tools (Ollama, Langflow, ComfyUI) with Nuclei

Unauthenticated self-hosted AI panels (Ollama, Langflow, ComfyUI) are shadow IT. See how Nuclei scans exposed AI tools and closes the exposure window.

Threat insightsWAFE-commerceCredential StuffingATO

E-commerce Credential Stuffing: WAF Rules for ATO Defense (JA4, ASN Thresholds)

Credential stuffing detection for e-commerce WAF: JA4 fingerprinting, ASN thresholds, and graduated responses that stop bots without blocking customers.

Threat insightsOPARegoMCP

Governing AI Agent MCP Tool Calls with OPA/Rego

OPA Rego permissions for AI agent MCP tool calls: how to interpose a policy-as-code decision before every call, based on role, data sensitivity, and time.

Threat insightsThreat intelDétection

Wireless ADB Abuse: How Android Malware Bypasses SMB Defenses

RedHook malware exploits Wireless ADB for shell access. Learn the MITRE ATT&CK techniques and how SMBs can detect/respond to this mobile threat.

Threat insightsFalcoTetragonCryptojacking

Detecting Container Cryptojacking with Falco and Tetragon

Cryptojacking Kubernetes Falco detection: the rule that catches a binary launched from /tmp, mining pool connections, and what still needs a human before a kill

Threat insightsWAFLLM SecuritySSRFPrompt Injection

Protecting an LLM API with WAF Rules: SSRF and Prompt Injection

A WAF rule set (OWASP CRS/Coraza) placed in front of an LLM API blocks SSRF payloads and prompt injection attempts before they ever reach the application code.

Threat insightsNucleiJoomlaCVEWebshell

SMB Sites: Scanning Joomla Plugin Upload CVEs with Nuclei (Webshell)

Joomla plugin upload vulnerability detection CVE: a KEV wave hits SP Page Builder, Joomlack, iCagenda, Balbooa Forms. A Nuclei method against false positives.

Threat insightsNucleiAI SecurityVulnerability Scanning

Scanning Self-Hosted AI Stack CVEs with Nuclei (Langflow, ComfyUI, LiteLLM)

Langflow, ComfyUI, LiteLLM run in-house with no CVE tracking. Nuclei templates, anti false-positive matchers, and EPSS/KEV prioritization for these AI stacks.

Threat insightsSigmaLOLBinsDetectionRansomware

Detecting 2026 LOLBins and Living-off-the-Land with Sigma

LOLBins living off the land detection: how to catch MSBuild, regsvr32, rundll32 abuse via CommandLine and ParentImage, without drowning the team in false positives.

Threat insightsmacOSYARAInfostealerClickFix

macOS Infostealers 2026: YARA Rules for CrashStealer, PamStealer and ClickFix DMGs

macOS infostealer ClickFix detection: YARA rules against trojanized DMGs, direct Keychain access and fake verification prompts, with no false positives.

Threat insightsAzure ADPassword SprayIOCEntra ID

Azure CLI Password Spray: Building an IOC Feed (IPv6/ASN) and Detecting Bursts

Azure CLI password spray detection: build an ASN/IPv6 IOC feed (AS32167 LSHIY), tune Entra ID thresholds, and avoid false positives on legitimate CLI usage.

Product updatesT1542.001KEVDétection

New ThreatClaw Detections: Exploited CMS Flaws & Firmware Risks

This week, ThreatClaw expands coverage for actively exploited CMS vulnerabilities (CVE-2026-48908, CVE-2026-56290) and suspicious firmware updates (T1542.001), hardening defenses against supply-chain attacks.

Threat insightsFalcoTetragoneBPFAI Agents

Detecting Anomalous AI Agent Behavior at Runtime with Falco and Tetragon

Falco and Tetragon runtime detection catches an AI agent breaking its sandbox: rogue tool calls, unexpected process spawns, prompt-driven escalation attempts.

Threat insightsIOCSupply ChainGitHubInfostealer

Fake GitHub Repos: IOC Feed for the Typosquatting Infostealer Campaign (292+ Repos)

292+ typosquatted GitHub repos push infostealers disguised as security tools and crypto wallets. Building an IOC feed (hashes, C2) to detect them.

Threat insightsSigmaElasticECSDetection

Converting Sigma Rules to Elastic (ECS, Lucene, ES|QL): A Practical Guide

Sigma is generic; Elastic queries indexed ECS documents via Lucene, EQL, or ES|QL. Here is how to convert your Sigma rules with pySigma, the ecs_windows pipeline, and how to dodge the mapping traps.

Threat insightsSigmaQRadarAQLDetection

Converting Sigma Rules to IBM QRadar (AQL): A Practical Guide

How to convert Sigma rules into AQL queries with pySigma, choose between the fields pipeline and the payload fallback, avoid queries that scan everything, and maintain it at scale.

Threat insightsSigmaMicrosoft SentinelKQLDetection

Converting Sigma Rules to Microsoft Sentinel (KQL): A Practical Guide

How to convert Sigma rules to KQL for Microsoft Sentinel and Defender XDR with pySigma: microsoft_xdr vs sentinel_asim pipelines, field mapping, pitfalls, and scaling.

Threat insightsSigmaSplunkSIEMDetection

Converting Sigma Rules to Splunk (SPL): A Practical Guide

How to convert Sigma rules into SPL queries with pySigma, handle CIM field mapping, avoid rules that match nothing, and maintain the pipeline at scale.

Threat insightsSuricataJA4NIDS

Detecting Encrypted C2 with JA4+ Fingerprinting in Suricata

JA3 struggles against TLS 1.3. Configure JA4 in Suricata, write a ja4.hash detection rule, and correlate with SNI to catch encrypted C2 and data exfiltration.

Threat insightsEPSSKEVVulnerabilitiesPrioritization

Prioritizing Vulnerabilities with EPSS and KEV: A Method for SMBs

Vulnerability prioritization with EPSS and KEV for SMBs: turn hundreds of open CVEs into a handful of real actions, with a worked numeric example and daily re-scoring.

Threat insightsNucleiCI/CDGitHub ActionsDevSecOps

Integrating Nuclei into a CI/CD GitHub Actions Pipeline for Continuous Scanning

A step-by-step guide to Nuclei CI/CD GitHub Actions integration: post-deploy job, tight scoping, targeted alerting, and template management past week one.

Threat insightsThreat intelDétection

SharePoint Under Siege: SMBs Must Act on Critical Deserialization Flaw

CISA warns of active exploitation of a SharePoint deserialization flaw. Learn the MITRE ATT&CK techniques, detection strategies, and how SMBs can respond.

Threat insightsSigmaDetection EngineeringAtomic Red Team

Testing Sigma Rules Before Production: Fixtures, Regression, and Shadow Mode

How to test Sigma rules before production: true/false-positive fixtures, regression testing with Atomic Red Team, shadow mode, and coverage backtesting.

Product updatesT1003T1003.001KEVDétection

New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats

This week’s update expands coverage for 20+ exploited CVEs, critical web vulnerabilities, and 20+ malware families, hardening defenses against initial access and persistence threats.

Threat insightsSuricataSnortNIDSNetwork Detection

Suricata vs Snort in 2026: Which NIDS Engine to Choose

Suricata vs Snort compared on architecture, rule compatibility, ICS/OT coverage, and migration steps, to help you pick a NIDS engine on technical merit.

Product updatesT1003T1003.001KEVDétection

New ThreatClaw Coverage: Exploited CVEs, Ransomware Evasion & BYOVD Risks

This week’s ThreatClaw update expands detection for 4 exploited CVEs, ransomware staging techniques, BYOVD attacks, and 258 new Sigma rules targeting enterprise threats.

Threat insightsSigmaCI/CDDetection EngineeringDevSecOps

Sigma Detection-as-Code: A CI/CD Pipeline to Test and Version Your Rules

A Sigma pipeline CI/CD detection as code setup: validate, translate, test, deploy, with ATT&CK fixtures and experimental-to-stable governance for untested rules.

Threat insightsThreat intelDétection

June 2026 Patch Tuesday: RCE Flaws in RDP & HTTP Stack Threaten SMBs

Microsoft’s June 2026 Patch Tuesday fixes 32 critical RCE flaws in RDP, HTTP.sys, and Hyper-V. Learn how SMBs can detect and respond to these high-risk threats.

Threat insightsYARAFalse PositivesDetection EngineeringPerformance

Reducing YARA False Positives at Scale: Tuning and Performance for the Enterprise

A YARA rule that fires on clean software drowns the analyst and destroys trust. A method to measure, fix and speed up your rules across a large estate.

Threat insightsRed TeamAIOWASPAI Act

LLM Red Teaming: Testing Your AI Agents and Chatbots Before Production

LLM red teaming and AI agent security testing with Garak, PyRIT, and Promptfoo: a complete method to test chatbots before production, aligned with OWASP and the AI Act.

Threat insightsMISPSTIXIOCThreat Intelligence

Building an IOC Pipeline with MISP and STIX: The Complete Guide

A complete guide to building an IOC pipeline with MISP and STIX: sourcing, deduplication, anti-false-positive warninglists, lifecycle, and detection delivery.

Threat insightsNucleiVulnerability ScanningKEVFleet Scanning

Nuclei at Scale: Vulnerability Scanning and KEV Rapid Response

Scan a fleet with Nuclei without saturating it, prioritize by KEV/EPSS and respond in hours to a CISA advisory: the method for vulnerability scanning at scale.

Threat insightsSigmaDetection EngineeringSIEM

Detection Engineering with Sigma: Where to Start

Getting started with Sigma detection engineering: rule anatomy, sigma-cli tooling, the hypothesis-test-promote loop, and the false-positive traps to avoid.

Threat insightsPolicy as CodeKubernetesOPACompliance

Policy-as-Code: Securing Kubernetes and IaC with OPA/Rego and Kyverno

Policy as code with OPA Rego and Kubernetes lets you deny a privileged pod before it ever starts. OPA/Rego vs Kyverno, real examples, testing, and NIS2/DORA proof.

Threat insightsWAFOWASP CRSApplication Security

Open-Source WAF: Protecting Web Apps with OWASP CRS (Coraza and ModSecurity)

Deploy an open-source WAF (Coraza, ModSecurity) with OWASP CRS: paranoia levels, endpoint-scoped exclusions, and tuning to cut CRS false positives for SMBs.

Threat insightsKuberneteseBPFRuntime SecurityFalco

Cloud-Native Runtime Security: Detecting Container Threats with Falco and Tetragon (eBPF)

Image scanning never sees what happens at runtime. A practical guide to container runtime security with eBPF using Falco and Tetragon: rules, examples, and pitfalls.

Threat insightsYARAThreat HuntingDFIRDetection

YARA for Threat Hunting and DFIR: The Complete Guide

YARA goes beyond antivirus scanning: memory hunting, DFIR triage, retrohunting. A yara threat hunting dfir guide with commands, playbook, noise reduction.

Threat insightsNIDSSuricataNetwork Detection

Network Intrusion Detection for SMBs: Catching Attacks with Suricata and Snort

Network intrusion detection NIDS: where Suricata sees what an EDR cannot, the anatomy of a rule, and why a curated rule pack beats a raw, noisy rule feed.

Threat insightsSuricataNIDSDetection Rules

Writing Your First Suricata Rule: Syntax, a CVE Example, and False-Positive Testing

A practical guide to writing a Suricata rule: header structure, modern sticky buffers, a before/after CVE example, pcap testing, and the false-positive trap.

Threat insightsThreat IntelligenceIOCFeedMISP

Choosing and Operating an IOC Feed: Beyond the List of Addresses That Blocks Your Own Customers

A raw list of IPs, domains and hashes is easy to find and nearly worthless. The value is in choosing the right feed and operating it: licensing, corroboration, aging, and the rule that keeps you from blocking your own CDN.

Threat insightsNucleiCVEDetectionVulnerability Scanning

Writing a Nuclei Template for a CVE: From Advisory to a Template That Fires (Without False Positives)

A CVE drops, the advisory is public, but no Nuclei template exists yet. Here is how to write a clean one: start from the fact, build the matchers, and above all prove it fires on a vulnerable target while staying silent on a patched one.

Threat insightsSigmaCVEDetection EngineeringMITRE ATT&CK

Writing a Sigma Rule for a CVE or Technique: From Behavior to Detection That Does Not Drown the SOC

An attack technique or the exploitation of a CVE is described in a report. You want to detect it in your logs. Here is how to write a Sigma rule that fires on the real behavior, without flooding the SOC with false positives, and how to prove it.

Threat insightsYARAMalwareDFIRDetection

Writing a YARA Rule for Malware: From Sample to a Reliable Signature (Without False Positives)

You get a malware sample, a DFIR engagement, a sandbox, a feed. You want to detect the whole family across your estate. Here is how to write a YARA rule that catches the threat without firing on legitimate software, and how to prove it.

Threat insightsDORAFinance

DORA: What the Financial Sector Needs to Know in 2026

The 5 pillars of the Digital Operational Resilience Act, incident reporting within 4h/72h, and ICT third-party management. A practical DORA compliance guide.

Threat insightsCRAIoT

Cyber Resilience Act: The Impact on IoT Manufacturers

Manufacturer obligations, SBOM, 5-year security updates, and CE marking: everything the CRA changes for connected products.

Threat insightsAI ActIA

AI Act and Cybersecurity: What It Changes for Detection Tools

Risk classification, transparency obligations, and AI detection tool compliance. How ThreatClaw stays ahead of the AI Act.

Threat insightsSupply ChainSBOM

Supply Chain Attacks: From SolarWinds to XZ Utils, Lessons and Defenses

Analysis of major supply chain attacks, the role of SBOM, Syft/Grype tooling, and cryptographic signature verification.

Threat insightsZero TrustNIST

Zero Trust in 2026: A Practical Guide for Enterprises

Concrete Zero Trust implementation guide: NIST 800-207, micro-segmentation, identity-first approach, and phased deployment.

Threat insightsCryptoQuantique

Post-Quantum Cryptography: When to Migrate?

ML-KEM, ML-DSA, harvest now decrypt later threat: a post-quantum cryptography migration guide for enterprises.

Threat insightsSantéRansomware

Cyberattacks on Hospitals: Healthcare as Target #1

ANSSI statistics, healthcare-targeted ransomware, NIS2 requirements for hospitals, and defense strategies.

Threat insightsOT/ICSIndustrie

OT/ICS Security: Protecting Industry from Cyber Threats

IT/OT convergence, Purdue model, Suricata/Zeek detection: a practical security guide for industrial systems.

Threat insightsDeepfakeSocial Eng.

Deepfakes and Social Engineering: The New Enterprise Threat

CEO fraud worth $25M, deepfake detection, team training: how enterprises must protect themselves.

Threat insightsMFAFIDO2

Passkeys and MFA: The End of Passwords?

FIDO2, MFA fatigue, phishing-resistant authentication: a complete guide to going passwordless in the enterprise.

Threat insightsANSSIFrance

ANSSI 2025 Threat Landscape Report: Key Takeaways

Analysis of the ANSSI 2025 Cyber Threat Landscape report: 2,209 reports, 1,366 incidents handled, 128 ransomware cases, and the 2026-2030 strategic priorities.

Threat insightsSecNumCloudSouveraineté

SecNumCloud: The Sovereign Label Changing the Game

ANSSI SecNumCloud certification, CLOUD Act protection, certified providers OVHcloud and 3DS Outscale, European EUCS framework, and NIS2 impact on sovereign hosting.

Threat insightsNIS2PME

NIS2: A Practical Compliance Guide for SMBs in 2026

The 10 measures of Art.21, notification deadlines, penalties, and how to automate your NIS2 compliance without blowing your budget.

Threat insightsXDREDR

XDR vs EDR: Which One to Choose in 2026?

EDR vs XDR vs NDR vs MDR comparison. CrowdStrike, SentinelOne, Microsoft Defender, HarfangLab. When each approach fits and how ThreatClaw completes the picture.

Threat insightsAssuranceCompliance

Cyber Insurance in 2026: What Insurers Now Require

Hardened market, premiums up 50%, cyber war and ransomware exclusions without MFA. Minimum requirements: EDR, MFA, 3-2-1 backup, and LOPMI Art.5 law.

Threat insightsASMRecon

ASM: Map Your Attack Surface Before Attackers Do

Attack Surface Management: shadow IT, forgotten assets, Shodan, Censys, Subfinder, CT log certificates. Why continuous scanning beats point-in-time audits.

Threat insightsSOCIA

AI-Automated SOC: The End of Ignored Alerts

4,500 alerts/day, 68% ignored. How AI transforms SOCs from alert fatigue to intelligent detection.

Threat insightsCTISTIX

CTI: Integrating Threat Intelligence into Your SOC

Complete Cyber Threat Intelligence guide: STIX 2.1, TAXII, CERT-FR feeds, CISA KEV, EPSS, GreyNoise, CrowdSec CTI, TLP, IoC scoring, and automatic enrichment.

Threat insightsK8sRuntime

Kubernetes Runtime Security: Beyond Image Scanning

CVE-2024-9042, CVE-2025-1767, runtime vs build-time security, eBPF, Falco, Network Policies, Pod Security Standards. ThreatClaw with Trivy and Grype.

Threat insightsÉlectionsAPT

Elections and Cybersecurity: Lessons from 2024-2025

Electoral interference by Midnight Blizzard and APT28, social media manipulation, political deepfakes, voting infrastructure protection. ANSSI and VIGINUM.

Threat insightsSIEMOpen Source

Open Source SIEM in 2026: Wazuh, ELK, or Autonomous Agent?

An unfiltered comparison of Wazuh, ELK Stack, and Graylog. Why SIEM alone is no longer enough, and how an AI agent completes the equation.

Threat insightsIoTBotnet

IoT and Botnets: The Invisible Threat of Connected Devices

Mirai legacy, IP cameras, routers, record DDoS botnets 2025, unpatched firmware, Cyber Resilience Act, network segmentation, and defenses.

Threat insightsAPTGéopolitique

APT 2025-2026: Mapping Active State-Sponsored Groups

Volt Typhoon, Salt Typhoon, Sandworm, APT28, Lazarus Group: mapping active state-sponsored APT groups, living-off-the-land techniques, and ANSSI 2025 references.

Threat insightsIncidentNIST

Cyber Incident Response: The 4 NIST Phases

The 4 NIST SP 800-61 phases, the 2:17 AM scenario, and how to cut dwell time from 194 days to minutes.

Threat insightsRSSIIA

Outsourced CISO: How AI Fills the Gap

3.5 million unfilled cybersecurity positions. The outsourced CISO and AI agent as a force multiplier.

Threat insightsRansomwareML

Detecting Ransomware Before Encryption Starts

Ransomware kill chain, early warning signs, and ML behavioral detection. How to stop the attack before encryption begins.

Threat insightsAuditContinu

IT Security Audit: From One-Off to Continuous

Pentest, vulnerability scan, organizational audit. Why the annual model is obsolete and how to switch to continuous auditing.

Threat insightsRGPDCNIL

GDPR Art.33: Notifying the DPA Within 72 Hours

What constitutes a data breach, the DPA notification process, the 72-hour deadline, and how to automate detection and reporting.

Threat insightsDockerK8s

Docker and Kubernetes Security: The 10 Risks

The 10 major risks in containerized environments and the tools to address them: Trivy, Grype, Docker Bench, Syft.

Threat insightsPentestScan

Pentest vs Vulnerability Scan: Which Should You Choose?

Human pentest vs automated scanning: costs, depth, frequency. A practical guide to choosing based on your context and maturity.