© 2026 Hashnode
In this walkthrough, we investigate the SOC163 – Suspicious Certutil.exe Usage alert in the LetsDefend platform. 🔎 Alert Overview The monitoring dashboard shows an alert triggered for suspicious usage of certutil.exe. Certutil.exe is a legitimate ...

Today we’re investigating another LetsDefend alert: SOC164 – Suspicious Mshta Behavior This alert focuses on detecting suspicious usage of a legitimate Windows binary often abused by attackers. 🔎 Alert Overview From the monitoring page, we are pro...

Most small business owners worry about phishing emails, ransomware, or weak passwords. Few of them realize that one of the biggest risks today is something far quieter: Shadow APIs. And unlike obvious cyber threats, shadow APIs don’t announce themsel...

Modern digital communication happens in milliseconds, yet behind every click lies a complex system of networks, protocols, and data exchange. Whether you're browsing a website, sending a message, or analyzing traffic in Wireshark, everything depends ...
