Threat insights

PhobosRansomwareSigmaDetection EngineeringShadow Copies

Detecting Phobos: What a Ransomware Actually Does, and the Rule That Stops It

We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.

Botnet / LoaderEmotetThreat DetectionYARA

Emotet Botnet Resurfaces: ThreatClaw Adds YARA Detection for SMBs

Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.

DrokbkRemote Access TrojanThreat DetectionYARA

Drokbk RAT Detection: ThreatClaw Adds Coverage for Stealthy Malware

Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.

DosiaMalwareThreat DetectionYARA

Dosia Malware Detection: ThreatClaw Adds YARA Rules for SMBs

Dosia malware targets SMBs with obfuscation and tool transfer tactics. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this threat effectively.

Threat IntelDetection

MacSync Stealer: Malvertising Lures SMBs into macOS Threats

Fake AI install guides via malvertising deliver MacSync Stealer. Learn ATT&CK techniques and SMB detection/response strategies for macOS threats.

DarkgateLoaderThreat DetectionYARA

Darkgate Loader Threat Detection: ThreatClaw Adds YARA Coverage

Darkgate, a sophisticated malware loader, evades defenses with obfuscation and process injection. Learn how ThreatClaw’s new YARA rules help SMBs and MSSPs detect this threat.

CryptolockerRansomwareThreat DetectionYARA

Cryptolocker Ransomware: Detection Now in ThreatClaw for SMBs & MSSPs

ThreatClaw adds YARA-based detection for Cryptolocker ransomware. Learn how this threat encrypts data, disrupts recovery, and why SMBs/MSSPs must act now.

Shadow AIDetection EngineeringSigmaLLM Security

Detecting Shadow AI: Finding Unsanctioned AI Use in Your Logs

Shadow AI is shadow IT's faster, leakier cousin. This guide covers what it is, why it is a real risk, and — the part nobody writes about — how to actually detect unsanctioned AI use in your network, proxy and endpoint logs, with a working Sigma rule.

Valid AccountsInsider ThreatThreat DetectionSigma

The DGFiP Breach: An Attack No Antivirus Could Ever Flag

Valid credentials, internal VPN, business application: the French tax authority breach shows why behavioural detection beats signatures every time.

SIEMWazuhOpen SourceSigma

Open Source SIEM in 2026: An Honest Comparison of Wazuh, Elastic, Security Onion and Graylog

Wazuh, Elastic/Security Onion, Graylog, OpenSearch — a genuinely balanced comparison of free and open-source SIEM options for SMBs, with real resource requirements, a Sigma-ingestion table, and the part every vendor page skips: what happens after install day.

OWASPLLM SecurityPrompt InjectionAI Red Teaming

OWASP Top 10 for LLM Applications: A Practical Testing Reference

The full OWASP Top 10 for LLM Applications (2025 edition), explained the way most write-ups skip: for each of the 10 risks, what it is, a concrete example, and — the part that matters — how you actually test or detect it.

CryptbotInfostealerThreat DetectionYARA

Cryptbot Infostealer Detection: ThreatClaw Enhances SMB Protection

Cryptbot infostealer targets credentials and session data. Learn how ThreatClaw’s new YARA rules help MSSPs and SMBs detect and mitigate this persistent threat.

CosmicdukeTargeted ImplantThreat DetectionYARA

Cosmicduke Malware Detection: ThreatClaw Adds YARA Rules for Targeted Implant

ThreatClaw now detects Cosmicduke, a stealthy targeted implant. Learn how this malware operates, its MITRE ATT&CK techniques, and why SMBs/MSSPs must stay vigilant.

ContiRansomwareThreat DetectionYARA

Conti Ransomware: Detection Coverage & Why SMBs Must Act Now

Conti ransomware remains a top threat to SMBs. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it with zero false positives.

CobaltCommand-And-Control FrameworkThreat DetectionYARA

Cobalt C2 Framework Detection: ThreatClaw Adds YARA Coverage

ThreatClaw now detects Cobalt, a sophisticated command-and-control framework. Learn how this threat operates and why SMBs/MSSPs must defend against it.

CloudeyeLoaderThreat DetectionYARA

Cloudeye Loader Detection: ThreatClaw Shields SMBs from Stealthy Malware

Cloudeye, a sophisticated malware loader, evades defenses with obfuscation and process injection. ThreatClaw now delivers YARA-based detection to protect SMBs and MSSPs.

Threat IntelDetection

SMBs on Alert: Three Actively Exploited Vulnerabilities Demand Action

CISA adds three critical vulnerabilities to its KEV catalog. Learn the MITRE ATT&CK techniques, detection strategies, and how SMBs can respond effectively.

BlankgrabberInfostealerThreat DetectionYARA

Blankgrabber Infostealer: Detection Now Live in ThreatClaw Feeds

Blankgrabber infostealer targets credentials and session data. Learn how this malware operates and why ThreatClaw’s YARA rules now detect it for SMBs and MSSPs.

BkransomwareRansomwareThreat DetectionYARA

Bkransomware Detection: ThreatClaw Adds YARA Rules for SMBs

Bkransomware targets SMBs with encryption and recovery disruption. ThreatClaw now ships 39 validated YARA rules to detect this emerging ransomware threat.

Banking TrojanBeatbankerThreat DetectionYARA

Beatbanker Banking Trojan: Detection Now in ThreatClaw Feeds

Beatbanker is a stealthy banking trojan targeting financial data. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it for SMBs and MSSPs.

BanbraBanking TrojanThreat DetectionYARA

Banbra Banking Trojan: Detection Now Live in ThreatClaw Feeds

Banbra banking trojan targets financial data via input capture and local system exfiltration. Learn how ThreatClaw now detects this threat for SMBs and MSSPs.

AvoslockerRansomwareThreat DetectionYARA

Avoslocker Ransomware: Detection Coverage for SMBs and MSSPs

Avoslocker ransomware targets SMBs with encryption and recovery disruption. Learn how ThreatClaw’s YARA rules now detect this threat to protect clients.

AspxspyMalwareThreat DetectionYARA

Aspxspy Malware Detection: ThreatClaw Adds Coverage for Stealthy Web Shell

Aspxspy malware targets SMBs via obfuscated web shells. Learn how it operates, why it evades defenses, and how ThreatClaw now detects it with zero false positives.

AmadeyLoaderThreat DetectionYARA

Amadey Loader Detection: ThreatClaw Adds YARA Rules for SMBs & MSSPs

Amadey loader resurfaces as a persistent threat. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw’s new YARA rules help SMBs and MSSPs detect it.

Threat IntelDetection

Progress LoadMaster Flaw Exploited: SMBs Must Act Now

CISA warns of active exploitation of a Progress LoadMaster command injection flaw. Learn ATT&CK techniques and SMB detection/response steps.

AkiraRansomwareThreat DetectionYARA

Akira Ransomware: Detection Coverage & Why SMBs Must Act Now

Akira ransomware targets SMBs with double-extortion tactics. Learn how it operates, its MITRE ATT&CK techniques, and how ThreatClaw now detects it.

SigmaYARADetectionPlaybookCACAOATT&CKThreat IntelligenceRule Feed

Proven Detection, Not Scraped Rules: What Sets the ThreatClaw Feed Apart

A rule feed is not worth its rule count. It is worth the proof that the rules fire and what you do when they trigger. Tested on real engines, false-positive-proven, signed, and every rule ships an investigation playbook wired to our other engines.

Threat IntelDetection

Hard-Coded Passwords in Firewalls: SMBs Must Act Now

CVE-2026-20316 exposes Cisco Secure Firewall Management Center via hard-coded credentials. Learn ATT&CK techniques and SMB detection steps.

Threat IntelDetection

Zimbra Zero-Day Exploit: How SMBs Can Detect Email Theft Threats

A new Zimbra zero-day exploit enables email theft via phishing. Learn the MITRE ATT&CK techniques and how SMBs can detect and respond.

SigmaNucleiCVESharePointDetection

SharePoint CVE-2026-45659: The Deserialization That Leads to Warlock Ransomware

Deserialization of untrusted data yields RCE on on-premise SharePoint. In the KEV, exploited by Storm-2603. Here is the Sigma rule on w3wp and Nuclei detection.

IOCThreat intelSMBVulnerabilities

DBIR 2026: 96% of Ransomware Victims Are SMBs, Now What?

The Verizon 2026 report puts vulnerability exploitation ahead as the top initial access vector and confirms ransomware mainly hits SMBs. The concrete actions.

NucleiCVEVPNPAN-OSDetection

PAN-OS GlobalProtect CVE-2026-0257: The Cookie That Is Not Verified

A poorly validated override cookie opens an unauthorized GlobalProtect session. Score raised to 7.8, in the KEV, exploited. Nuclei detection and mitigation.

NucleiCVEMSPSupply chainDetection

SimpleHelp CVE-2026-48558: When Your MSP Becomes the Way In

An unsigned OIDC token grants technician access to SimpleHelp RMM. CVSS 10, in the KEV, exploited to deliver stealers. Nuclei detection and accounts to watch.

VelociraptorDFIRThreat huntingDetectionIncident response

Hunting an Edge Appliance Compromise with Velociraptor

After a VPN or firewall intrusion, the appliance service account pivots into AD. Here is how to hunt those traces across the whole estate with Velociraptor.

LLMRed teamPrompt injectionAIApplication security

When a Prompt Opens a Shell: RCE via Injection in AI Agents

Microsoft showed a single prompt can launch calc.exe via Semantic Kernel. CVE-2026-26030 and 25592 turn injection into RCE. How to test your own AI agents.

SigmaOAuthSaaSIdentityDetection

ShinyHunters: The OAuth Abuse That Bypasses MFA on Salesforce and M365

ShinyHunters hijacks trusted OAuth connections to exfiltrate CRM data without ever triggering MFA. Here is how to detect abusive consents and tokens.

SigmaYARARansomwareBYOVDDetection

The Gentlemen: The RaaS That Enters at the Edge and Neutralizes EDR

The Gentlemen gets in via compromised FortiGates, disables EDR with a vulnerable driver (BYOVD) and enumerates AD. Here are the Sigma and YARA rules to spot it.

SuricataCVEVPNRansomwareDetection

Check Point VPN: The Client Dictates Authentication (CVE-2026-50751)

One byte of the IKEv1 Vendor ID disables server-side verification. Exploited since May by a Qilin affiliate. Here are the IOCs, the Suricata rule, and the fix.

WAFCVECitrixRansomwareDetection

Citrix NetScaler: CitrixBleed Strikes Again (CVE-2026-8451), the WAF as Shield

A NetScaler memory leak in SAML IdP mode replays the CitrixBleed scenario: token theft, MFA bypass, DragonForce. Here is WAF virtual patching.

Threat intelDétection

SQL Injection to Persistence: How SMBs Can Detect Post-Compromise Threats

Threat actors exploit SQL injection to gain access, then modify environments for persistence. Learn ATT&CK techniques and SMB detection strategies.

FalcoKubernetesCloudDetectionOPA

Kubernetes Container Escape to Cloud Pivot: Detect at Runtime

Google observes clusters attacked within 18 minutes and escapes via privileged pods. Here is runtime detection with Falco and admission guardrails with OPA.

SigmaQuick AssistRansomwareDetectionSocial engineering

Payouts King: The Fake Teams Support That Installs Edgecution via Quick Assist

Fake IT support on Teams pushes the victim to open Quick Assist, then installs Edgecution, an Edge extension that escapes the sandbox. The Sigma detection.

NucleiCVESonicWallDetectionKEV

SonicWall SMA1000: Two Zero-Days Exploited, How to Detect and Prioritize

CVE-2026-15409 (SSRF, CVSS 10) and CVE-2026-15410 (root RCE) hit SMA1000 appliances. In the KEV catalog. Here are the fixed versions, IOCs, and Nuclei detection.

SigmaEntra IDIdentityDetectionPhishing

Entra ID: The Fake Passkey Enrollment That Buys Durable Persistence

Via vishing, actor O-UNC-066 registers its own FIDO2 passkey in the victim's account. Detect the method addition correlated with a risky sign-in.

DetectionFeedsSIEMDetection Engineering

How to Evaluate a Detection Rule Feed: A Buyer's Checklist

Rule count is a vanity metric. Here is the checklist that actually decides whether a Sigma, YARA or NIDS detection feed is worth paying for: license for resale, deduplication, conversion coverage, false-positive discipline, signature and maintenance cadence.

IOCThreat IntelligenceFeedsMISP

IOC Feeds Compared: abuse.ch, OTX, MISP and Curated Aggregation

The best IOC feeds are largely free. So what do you actually pay for? A practical comparison of abuse.ch, AlienVault OTX, MISP and commercial threat intel, and where a curated aggregation layer earns its place.

YARASupply chainnpmDetectionDevSecOps

npm: --ignore-scripts No Longer Enough, the Payload Fires at Import

The @asyncapi package compromise runs its payload at module load, not at install. Why --ignore-scripts fails and how to detect it with YARA.

NucleiVulnerability ScanningFeedsKEV

Nuclei Template Feeds: Community Templates, the Volume Problem, and KEV/EPSS Prioritization

How to prioritize Nuclei templates: cut by severity, fingerprint the stack, then rank by CISA KEV and EPSS so you scan what is actually exploited first. A concrete workflow, plus where a curated feed saves the work.

SigmaDetectionSIEMFeeds

Sigma Rule Feeds Compared: SigmaHQ, SOC Prime, Valhalla and Curated Alternatives

SigmaHQ is free, so why pay for a Sigma rule feed? A practical comparison of the public corpus, SOC Prime, Nextron Valhalla and curated feeds, with the criteria that actually matter for a SOC or MSSP.

SuricataNIDSNetworkFeeds

Suricata and NIDS Rulesets Compared: ET Open, ET Pro and Curated Alternatives

ET Open is free, ET Pro and Talos are paid, and curated feeds sit in between. A practical comparison of Suricata and Snort rulesets for network detection, with the criteria that matter for a SOC or MSSP.

YARAMalwareDFIRFeeds

YARA Rule Feeds Compared: Valhalla, Open Sources and When a Curated Feed Pays Off

Nextron Valhalla is the reference YARA feed, and there are strong free sources too. A practical comparison for EDR, DFIR and threat hunting, with the criteria that decide whether a curated YARA feed is worth paying for.

SigmaClickFixDetectionRansomwareSMB

ClickFix: From Fake CAPTCHA to Ransomware, a Reusable Sigma RunMRU Rule

ClickFix tricks users into pasting a PowerShell command via Win+R. Detect it through the RunMRU key and encoded arguments, before ACR Stealer or Interlock lands.

IOCPhishingRansomwareSMBDetection

Fake Interpol Emails: The Ransomware Aimed Straight at SMBs

A campaign impersonates Interpol to trap SMBs: Proton Drive link, encrypted archive, executable disguised as a video. The indicators and the detection rule.

YARASupply chainnpmRustDetection

IronWorm: A Rust-Built npm Worm That Steals Your Cloud and AI Keys

IronWorm hides a Rust binary triggered at preinstall, harvests cloud and AI keys, then self-propagates via GitHub. Here is the YARA rule to detect it.

AI AgentsRansomwareThreat Detection

JADEPUFFER: Detecting the First Autonomous AI-Agent Ransomware

AI agent ransomware detection: how JADEPUFFER encrypted victims without a human operator, and the correlation method that catches it without false positives.

OPA RegoHuman-in-the-LoopRemediation

Keeping Humans in the Loop: Rego Approval Gates Before AI Agent Remediation

An OPA Rego policy enforces mandatory human approval before AI agent remediation runs: automatic isolation, sign-off required for any destructive action.

WAFSEOBotsOWASP CRS

Blocking AI Scraper Bots (GPTBot, LLM Crawlers) Without Breaking Your SEO: OWASP CRS WAF Rules

GPTBot, ClaudeBot and Bytespider eat your bandwidth and content. How to block them with WAF rules, without touching Googlebot or hurting your search rankings.

LLM SecurityRed TeamAI Act

Garak vs PyRIT vs Promptfoo: Choosing Your LLM Red Team Tools

A comparison of LLM red team tools: Garak scans the raw model, PyRIT runs multi-turn attacks, and Promptfoo tests the application in CI/CD before production.

SigmaInfostealerLOLBinsDetectionPowerShell

VEIL#DROP: A PowerShell Loader Hidden Behind Blogger Pages

VEIL#DROP delivers PureLogs in memory via a fake PDF JavaScript and trusted Blogspot pages. Here is the chain, the fallback LOLBins, and Sigma detection.

ComplianceNIS2RegulationSigma

NIS2: France Before the CJEU, What the Deadline Changes for Companies

The Commission referred France to the CJEU on July 8, 2026 for failing to transpose NIS2. Penalties loom and the resilience law is delayed: what to anticipate.

Red TeamMCPPrompt Injection

Red-Teaming an MCP Server: Testing Indirect Prompt Injection to Tool Execution

How to red-team an MCP server against indirect prompt injection: verify a poisoned document cannot reach a tool call, file access, or command execution.

NucleiShadow AIExposure

Shadow AI: Scanning Exposed Self-Hosted AI Tools (Ollama, Langflow, ComfyUI) with Nuclei

Unauthenticated self-hosted AI panels (Ollama, Langflow, ComfyUI) are shadow IT. See how Nuclei scans exposed AI tools and closes the exposure window.

WAFE-commerceCredential StuffingATO

E-commerce Credential Stuffing: WAF Rules for ATO Defense (JA4, ASN Thresholds)

Credential stuffing detection for e-commerce WAF: JA4 fingerprinting, ASN thresholds, and graduated responses that stop bots without blocking customers.

OPARegoMCP

Governing AI Agent MCP Tool Calls with OPA/Rego

OPA Rego permissions for AI agent MCP tool calls: how to interpose a policy-as-code decision before every call, based on role, data sensitivity, and time.

Threat intelDétection

Wireless ADB Abuse: How Android Malware Bypasses SMB Defenses

RedHook malware exploits Wireless ADB for shell access. Learn the MITRE ATT&CK techniques and how SMBs can detect/respond to this mobile threat.

FalcoTetragonCryptojacking

Detecting Container Cryptojacking with Falco and Tetragon

Cryptojacking Kubernetes Falco detection: the rule that catches a binary launched from /tmp, mining pool connections, and what still needs a human before a kill

WAFLLM SecuritySSRFPrompt Injection

Protecting an LLM API with WAF Rules: SSRF and Prompt Injection

A WAF rule set (OWASP CRS/Coraza) placed in front of an LLM API blocks SSRF payloads and prompt injection attempts before they ever reach the application code.

NucleiJoomlaCVEWebshell

SMB Sites: Scanning Joomla Plugin Upload CVEs with Nuclei (Webshell)

Joomla plugin upload vulnerability detection CVE: a KEV wave hits SP Page Builder, Joomlack, iCagenda, Balbooa Forms. A Nuclei method against false positives.

NucleiAI SecurityVulnerability Scanning

Scanning Self-Hosted AI Stack CVEs with Nuclei (Langflow, ComfyUI, LiteLLM)

Langflow, ComfyUI, LiteLLM run in-house with no CVE tracking. Nuclei templates, anti false-positive matchers, and EPSS/KEV prioritization for these AI stacks.

SigmaLOLBinsDetectionRansomware

Detecting 2026 LOLBins and Living-off-the-Land with Sigma

LOLBins living off the land detection: how to catch MSBuild, regsvr32, rundll32 abuse via CommandLine and ParentImage, without drowning the team in false positives.

macOSYARAInfostealerClickFix

macOS Infostealers 2026: YARA Rules for CrashStealer, PamStealer and ClickFix DMGs

macOS infostealer ClickFix detection: YARA rules against trojanized DMGs, direct Keychain access and fake verification prompts, with no false positives.

Azure ADPassword SprayIOCEntra ID

Azure CLI Password Spray: Building an IOC Feed (IPv6/ASN) and Detecting Bursts

Azure CLI password spray detection: build an ASN/IPv6 IOC feed (AS32167 LSHIY), tune Entra ID thresholds, and avoid false positives on legitimate CLI usage.

FalcoTetragoneBPFAI Agents

Detecting Anomalous AI Agent Behavior at Runtime with Falco and Tetragon

Falco and Tetragon runtime detection catches an AI agent breaking its sandbox: rogue tool calls, unexpected process spawns, prompt-driven escalation attempts.

IOCSupply ChainGitHubInfostealer

Fake GitHub Repos: IOC Feed for the Typosquatting Infostealer Campaign (292+ Repos)

292+ typosquatted GitHub repos push infostealers disguised as security tools and crypto wallets. Building an IOC feed (hashes, C2) to detect them.

SigmaElasticECSDetection

Converting Sigma Rules to Elastic (ECS, Lucene, ES|QL): A Practical Guide

Sigma is generic; Elastic queries indexed ECS documents via Lucene, EQL, or ES|QL. Here is how to convert your Sigma rules with pySigma, the ecs_windows pipeline, and how to dodge the mapping traps.

SigmaQRadarAQLDetection

Converting Sigma Rules to IBM QRadar (AQL): A Practical Guide

How to convert Sigma rules into AQL queries with pySigma, choose between the fields pipeline and the payload fallback, avoid queries that scan everything, and maintain it at scale.

SigmaMicrosoft SentinelKQLDetection

Converting Sigma Rules to Microsoft Sentinel (KQL): A Practical Guide

How to convert Sigma rules to KQL for Microsoft Sentinel and Defender XDR with pySigma: microsoft_xdr vs sentinel_asim pipelines, field mapping, pitfalls, and scaling.

SigmaSplunkSIEMDetection

Converting Sigma Rules to Splunk (SPL): A Practical Guide

How to convert Sigma rules into SPL queries with pySigma, handle CIM field mapping, avoid rules that match nothing, and maintain the pipeline at scale.

SuricataJA4NIDS

Detecting Encrypted C2 with JA4+ Fingerprinting in Suricata

JA3 struggles against TLS 1.3. Configure JA4 in Suricata, write a ja4.hash detection rule, and correlate with SNI to catch encrypted C2 and data exfiltration.

EPSSKEVVulnerabilitiesPrioritization

Prioritizing Vulnerabilities with EPSS and KEV: A Method for SMBs

Vulnerability prioritization with EPSS and KEV for SMBs: turn hundreds of open CVEs into a handful of real actions, with a worked numeric example and daily re-scoring.

NucleiCI/CDGitHub ActionsDevSecOps

Integrating Nuclei into a CI/CD GitHub Actions Pipeline for Continuous Scanning

A step-by-step guide to Nuclei CI/CD GitHub Actions integration: post-deploy job, tight scoping, targeted alerting, and template management past week one.

Threat intelDétection

SharePoint Under Siege: SMBs Must Act on Critical Deserialization Flaw

CISA warns of active exploitation of a SharePoint deserialization flaw. Learn the MITRE ATT&CK techniques, detection strategies, and how SMBs can respond.

SigmaDetection EngineeringAtomic Red Team

Testing Sigma Rules Before Production: Fixtures, Regression, and Shadow Mode

How to test Sigma rules before production: true/false-positive fixtures, regression testing with Atomic Red Team, shadow mode, and coverage backtesting.

SuricataSnortNIDSNetwork Detection

Suricata vs Snort in 2026: Which NIDS Engine to Choose

Suricata vs Snort compared on architecture, rule compatibility, ICS/OT coverage, and migration steps, to help you pick a NIDS engine on technical merit.

SigmaCI/CDDetection EngineeringDevSecOps

Sigma Detection-as-Code: A CI/CD Pipeline to Test and Version Your Rules

A Sigma pipeline CI/CD detection as code setup: validate, translate, test, deploy, with ATT&CK fixtures and experimental-to-stable governance for untested rules.

Threat intelDétection

June 2026 Patch Tuesday: RCE Flaws in RDP & HTTP Stack Threaten SMBs

Microsoft’s June 2026 Patch Tuesday fixes 32 critical RCE flaws in RDP, HTTP.sys, and Hyper-V. Learn how SMBs can detect and respond to these high-risk threats.

YARAFalse PositivesDetection EngineeringPerformance

Reducing YARA False Positives at Scale: Tuning and Performance for the Enterprise

A YARA rule that fires on clean software drowns the analyst and destroys trust. A method to measure, fix and speed up your rules across a large estate.

Red TeamAIOWASPAI Act

LLM Red Teaming: Testing Your AI Agents and Chatbots Before Production

LLM red teaming and AI agent security testing with Garak, PyRIT, and Promptfoo: a complete method to test chatbots before production, aligned with OWASP and the AI Act.

MISPSTIXIOCThreat Intelligence

Building an IOC Pipeline with MISP and STIX: The Complete Guide

A complete guide to building an IOC pipeline with MISP and STIX: sourcing, deduplication, anti-false-positive warninglists, lifecycle, and detection delivery.

NucleiVulnerability ScanningKEVFleet Scanning

Nuclei at Scale: Vulnerability Scanning and KEV Rapid Response

Scan a fleet with Nuclei without saturating it, prioritize by KEV/EPSS and respond in hours to a CISA advisory: the method for vulnerability scanning at scale.

SigmaDetection EngineeringSIEM

Detection Engineering with Sigma: Where to Start

Getting started with Sigma detection engineering: rule anatomy, sigma-cli tooling, the hypothesis-test-promote loop, and the false-positive traps to avoid.

Policy as CodeKubernetesOPACompliance

Policy-as-Code: Securing Kubernetes and IaC with OPA/Rego and Kyverno

Policy as code with OPA Rego and Kubernetes lets you deny a privileged pod before it ever starts. OPA/Rego vs Kyverno, real examples, testing, and NIS2/DORA proof.

WAFOWASP CRSApplication Security

Open-Source WAF: Protecting Web Apps with OWASP CRS (Coraza and ModSecurity)

Deploy an open-source WAF (Coraza, ModSecurity) with OWASP CRS: paranoia levels, endpoint-scoped exclusions, and tuning to cut CRS false positives for SMBs.

KuberneteseBPFRuntime SecurityFalco

Cloud-Native Runtime Security: Detecting Container Threats with Falco and Tetragon (eBPF)

Image scanning never sees what happens at runtime. A practical guide to container runtime security with eBPF using Falco and Tetragon: rules, examples, and pitfalls.

YARAThreat HuntingDFIRDetection

YARA for Threat Hunting and DFIR: The Complete Guide

YARA goes beyond antivirus scanning: memory hunting, DFIR triage, retrohunting. A yara threat hunting dfir guide with commands, playbook, noise reduction.

NIDSSuricataNetwork Detection

Network Intrusion Detection for SMBs: Catching Attacks with Suricata and Snort

Network intrusion detection NIDS: where Suricata sees what an EDR cannot, the anatomy of a rule, and why a curated rule pack beats a raw, noisy rule feed.

SuricataNIDSDetection Rules

Writing Your First Suricata Rule: Syntax, a CVE Example, and False-Positive Testing

A practical guide to writing a Suricata rule: header structure, modern sticky buffers, a before/after CVE example, pcap testing, and the false-positive trap.

Threat IntelligenceIOCFeedMISP

Choosing and Operating an IOC Feed: Beyond the List of Addresses That Blocks Your Own Customers

A raw list of IPs, domains and hashes is easy to find and nearly worthless. The value is in choosing the right feed and operating it: licensing, corroboration, aging, and the rule that keeps you from blocking your own CDN.

NucleiCVEDetectionVulnerability Scanning

Writing a Nuclei Template for a CVE: From Advisory to a Template That Fires (Without False Positives)

A CVE drops, the advisory is public, but no Nuclei template exists yet. Here is how to write a clean one: start from the fact, build the matchers, and above all prove it fires on a vulnerable target while staying silent on a patched one.

SigmaCVEDetection EngineeringMITRE ATT&CK

Writing a Sigma Rule for a CVE or Technique: From Behavior to Detection That Does Not Drown the SOC

An attack technique or the exploitation of a CVE is described in a report. You want to detect it in your logs. Here is how to write a Sigma rule that fires on the real behavior, without flooding the SOC with false positives, and how to prove it.

YARAMalwareDFIRDetection

Writing a YARA Rule for Malware: From Sample to a Reliable Signature (Without False Positives)

You get a malware sample, a DFIR engagement, a sandbox, a feed. You want to detect the whole family across your estate. Here is how to write a YARA rule that catches the threat without firing on legitimate software, and how to prove it.

DORAFinance

DORA: What the Financial Sector Needs to Know in 2026

The 5 pillars of the Digital Operational Resilience Act, incident reporting within 4h/72h, and ICT third-party management. A practical DORA compliance guide.

CRAIoT

Cyber Resilience Act: The Impact on IoT Manufacturers

Manufacturer obligations, SBOM, 5-year security updates, and CE marking: everything the CRA changes for connected products.

AI ActIA

AI Act and Cybersecurity: What It Changes for Detection Tools

Risk classification, transparency obligations, and AI detection tool compliance. How ThreatClaw stays ahead of the AI Act.

Supply ChainSBOM

Supply Chain Attacks: From SolarWinds to XZ Utils, Lessons and Defenses

Analysis of major supply chain attacks, the role of SBOM, Syft/Grype tooling, and cryptographic signature verification.

Zero TrustNIST

Zero Trust in 2026: A Practical Guide for Enterprises

Concrete Zero Trust implementation guide: NIST 800-207, micro-segmentation, identity-first approach, and phased deployment.

CryptoQuantique

Post-Quantum Cryptography: When to Migrate?

ML-KEM, ML-DSA, harvest now decrypt later threat: a post-quantum cryptography migration guide for enterprises.

SantéRansomware

Cyberattacks on Hospitals: Healthcare as Target #1

ANSSI statistics, healthcare-targeted ransomware, NIS2 requirements for hospitals, and defense strategies.

OT/ICSIndustrie

OT/ICS Security: Protecting Industry from Cyber Threats

IT/OT convergence, Purdue model, Suricata/Zeek detection: a practical security guide for industrial systems.

DeepfakeSocial Eng.

Deepfakes and Social Engineering: The New Enterprise Threat

CEO fraud worth $25M, deepfake detection, team training: how enterprises must protect themselves.

MFAFIDO2

Passkeys and MFA: The End of Passwords?

FIDO2, MFA fatigue, phishing-resistant authentication: a complete guide to going passwordless in the enterprise.

ANSSIFrance

ANSSI 2025 Threat Landscape Report: Key Takeaways

Analysis of the ANSSI 2025 Cyber Threat Landscape report: 2,209 reports, 1,366 incidents handled, 128 ransomware cases, and the 2026-2030 strategic priorities.

SecNumCloudSouveraineté

SecNumCloud: The Sovereign Label Changing the Game

ANSSI SecNumCloud certification, CLOUD Act protection, certified providers OVHcloud and 3DS Outscale, European EUCS framework, and NIS2 impact on sovereign hosting.

NIS2PME

NIS2: A Practical Compliance Guide for SMBs in 2026

The 10 measures of Art.21, notification deadlines, penalties, and how to automate your NIS2 compliance without blowing your budget.

XDREDR

XDR vs EDR: Which One to Choose in 2026?

EDR vs XDR vs NDR vs MDR comparison. CrowdStrike, SentinelOne, Microsoft Defender, HarfangLab. When each approach fits and how ThreatClaw completes the picture.

AssuranceCompliance

Cyber Insurance in 2026: What Insurers Now Require

Hardened market, premiums up 50%, cyber war and ransomware exclusions without MFA. Minimum requirements: EDR, MFA, 3-2-1 backup, and LOPMI Art.5 law.

ASMRecon

ASM: Map Your Attack Surface Before Attackers Do

Attack Surface Management: shadow IT, forgotten assets, Shodan, Censys, Subfinder, CT log certificates. Why continuous scanning beats point-in-time audits.

SOCIA

AI-Automated SOC: The End of Ignored Alerts

4,500 alerts/day, 68% ignored. How AI transforms SOCs from alert fatigue to intelligent detection.

CTISTIX

CTI: Integrating Threat Intelligence into Your SOC

Complete Cyber Threat Intelligence guide: STIX 2.1, TAXII, CERT-FR feeds, CISA KEV, EPSS, GreyNoise, CrowdSec CTI, TLP, IoC scoring, and automatic enrichment.

K8sRuntime

Kubernetes Runtime Security: Beyond Image Scanning

CVE-2024-9042, CVE-2025-1767, runtime vs build-time security, eBPF, Falco, Network Policies, Pod Security Standards. ThreatClaw with Trivy and Grype.

ÉlectionsAPT

Elections and Cybersecurity: Lessons from 2024-2025

Electoral interference by Midnight Blizzard and APT28, social media manipulation, political deepfakes, voting infrastructure protection. ANSSI and VIGINUM.

SIEMOpen Source

Open Source SIEM in 2026: Wazuh, ELK, or Autonomous Agent?

An unfiltered comparison of Wazuh, ELK Stack, and Graylog. Why SIEM alone is no longer enough, and how an AI agent completes the equation.

IoTBotnet

IoT and Botnets: The Invisible Threat of Connected Devices

Mirai legacy, IP cameras, routers, record DDoS botnets 2025, unpatched firmware, Cyber Resilience Act, network segmentation, and defenses.

APTGéopolitique

APT 2025-2026: Mapping Active State-Sponsored Groups

Volt Typhoon, Salt Typhoon, Sandworm, APT28, Lazarus Group: mapping active state-sponsored APT groups, living-off-the-land techniques, and ANSSI 2025 references.

IncidentNIST

Cyber Incident Response: The 4 NIST Phases

The 4 NIST SP 800-61 phases, the 2:17 AM scenario, and how to cut dwell time from 194 days to minutes.

RSSIIA

Outsourced CISO: How AI Fills the Gap

3.5 million unfilled cybersecurity positions. The outsourced CISO and AI agent as a force multiplier.

RansomwareML

Detecting Ransomware Before Encryption Starts

Ransomware kill chain, early warning signs, and ML behavioral detection. How to stop the attack before encryption begins.

AuditContinu

IT Security Audit: From One-Off to Continuous

Pentest, vulnerability scan, organizational audit. Why the annual model is obsolete and how to switch to continuous auditing.

RGPDCNIL

GDPR Art.33: Notifying the DPA Within 72 Hours

What constitutes a data breach, the DPA notification process, the 72-hour deadline, and how to automate detection and reporting.

DockerK8s

Docker and Kubernetes Security: The 10 Risks

The 10 major risks in containerized environments and the tools to address them: Trivy, Grype, Docker Bench, Syft.

PentestScan

Pentest vs Vulnerability Scan: Which Should You Choose?

Human pentest vs automated scanning: costs, depth, frequency. A practical guide to choosing based on your context and maturity.