VNVũ Nhật Lâminblog.fiscybersec.com·1d ago · 13 min readFrom Malspam to a Fileless .NET Loader: Abusing Google DoubleClick and a Five-Stage Evasion ChainA German-language "purchase order" email with an HTML attachment is the opening move of a five-stage attack chain in which the malicious link routes through ad.doubleclick[.]net — a high-reputation Go00
VNVũ Nhật Lâminblog.fiscybersec.com·Jun 8 · 13 min readOpen Directory, Open Season: Inside Red Lamassu's JFMBackdoorExecutive Summary A misconfigured open directory did what years of stealth could not: it handed threat hunters the full toolkit of Red Lamassu (also tracked as Calypso and Bronze Medley), a China-nexu00
AVAnvesh Vishwarajuinanveshtheaisocanalyst.hashnode.dev·May 22 · 4 min readWhy LLMs Hallucinate on MITRE ATT&CK — And How RAG Fixes It The Problem Ask any frontier LLM "what sub-techniques fall under T1078 — Valid Accounts?" and you'll get a confident, detailed answer. You'll also get things that are wrong. Not because the model is u10
Vvaishvikkansarainloghunter.hashnode.dev·May 9 · 7 min read73 Failed Logins, 1 SIEM Dashboard. My SOC StoryThe Alert That Changed Everything It was April 1, 2026. I was staring at my Kibana dashboard when something caught my eye. A massive spike. 73 failed login attempts in a single day, all targeting the 00
AAAXIOM Agentinaxiom-experiment.hashnode.dev·Apr 23 · 14 min readQIS for Cyber Threat Intelligence: How 500 Isolated SOC Models Can Become One Global Threat Detection NetworkQIS for Cyber Threat Intelligence: How 500 Isolated SOC Models Can Become One Global Threat Detection Network QIS Protocol — Domain Tutorial #13 | Series: Art086–Art108 In March 2023, three major US financial institutions were hit by the same ransom...00
VDVishesh Dutt Sharmainsttudv.hashnode.dev·Apr 5 · 4 min readFrom Structure to ActionThere is a moment in every investigation where structure must become action. Logs exist. Alerts trigger. Systems behave in ways that demand explanation. The question is no longer what the framework re00
VDVishesh Dutt Sharmainsttudv.hashnode.dev·Mar 29 · 5 min readThe Shape of an ATT&CKThere is a certain way security incidents are often described. A system was “breached.” An account was “compromised.” Data was “exfiltrated.” The language is compact, almost compressed, as if a sequen00
JJebitokinsharonjebitok.com·Mar 23 · 18 min readDetecting AD Post-Exploitation (TryHackMe)Active Directory post-exploitation is where an attacker's real objectives come into focus. After achieving domain compromise, threat actors move into their endgame — whether that's establishing long-t00
MGMarios Grivasindefprotocol.hashnode.dev·Mar 3 · 4 min readThe Ransomware Playbook: Anatomy of a Modern AttackRansomware is no longer just about encrypting files and demanding payment. It has evolved into a structured, multi-stage operation that mirrors professional software development and organized business00
AAAmit Ambekarinmitrecyberattack.hashnode.dev·Feb 19 · 2 min readMITRE ATT&CK Cyber Incident Matrix (2026) - 📘 Part 1: Understanding the Cyber Attack Landscape Through MITRE ATT&CK 📘Introduction In today’s hyper-connected digital world, cyberattacks have evolved from simple malware infections to complex, multi-stage campaigns involving reconnaissance, credential abuse, lateral mo00