Posts on threat-intelligence
4 posts on threat-intelligence. Notes from public sources and my own test lab.
How to Catch Kerberoasting Without Event Logs
Searching for RC4-encrypted TGS requests alone isn't enough; I found in my test environment that AES-based Kerberoasting has a different detection path.
September 15, 2026·2 dk readnetwork-securityred-teamthreat-intelligence
How BTR.sys, a Signed Driver, Becomes a Weapon
Check Point's research shows how Defender's own signed boot-time driver can be weaponized at kernel level to delete files and registry entries—a paradox of code signing that validates signatures, not intent.
August 24, 2026·4 dk readexploitnetwork-securitysecurity
5 Siemens PLC Models Targeted by AI-Powered Attacks
A joint NSA and CISA alert shows Python scripts generated with AI infiltrating S7 PLCs; how do we manage this in systems with no patch window?
August 19, 2026·2 dk readai-securityiot-securitynetwork-security
Hunting for Treasure in the IOC Trash: The ‘Real’ Face of Threat Intel
Stop chasing static IPs and hashes. If you want to actually hurt an attacker, you need to climb the Pyramid of Pain and start targeting our TTPs.
February 9, 2026·5 dk readcybersecuritypythonred-teaming