MITRE ATT&CK Mapping Without Theater
MITRE ATT&CK mapping that drives decisions, not decoration — map to prioritize coverage, count only validated detections, and turn the matrix into a real backlog.
All writing
48 articles and counting.
MITRE ATT&CK mapping that drives decisions, not decoration — map to prioritize coverage, count only validated detections, and turn the matrix into a real backlog.
The Sigma rule lifecycle from hypothesis to production — status stages (experimental to stable), CI testing, tuning, versioning, and when to deprecate a rule.
A detection engineering workflow that ships — hypothesis to ATT&CK-mapped, data-validated, tested, version-controlled detections, gated by CI and measured.
A practical YubiKey deployment guide — phased FIDO2 rollout, closing phishable MFA fallbacks, detecting downgrade attacks, aligned to CISA and NIST SP 800-63-4.
BadUSB controls that survive contact with engineering teams — USB device control, HID allowlisting, USBGuard and WDAC, plus detection that does not block real work.
Evil twin access point defenses for blue teams — detect rogue APs with a WIDS, why 802.1X server-cert validation and WPA3 matter, plus a captive-portal DNS signal.
A WiFi deauthentication detection guide — spot deauth floods with a WIDS, why 802.11w PMF and WPA3 help (and where they fall short, CVE-2023-21061), plus hardening.
USB Rubber Ducky detection patterns for blue teams — spotting HID injection with Sigma, USB device control and AppLocker hardening, and MITRE ATT&CK mapping.
A defender's guide to Proxmark3 RFID security — auditing 125 kHz and MIFARE Classic credentials, detecting cloned badges, and migrating to DESFire EV3 and AES.
The real Flipper Zero NFC risk for security teams — what it can and cannot clone, MIFARE Classic weaknesses, access-control detection, and credential hardening.
How blue teams use HackRF One for defensive RF awareness — spectrum baselining, rogue-transmitter detection, a WIDS monitoring approach, and RF hardening.
An OAuth misconfiguration defensive review — redirect_uri validation, PKCE and state, detecting off-allowlist redirects and token anomalies, aligned to RFC 9700.