Posts on threat-intelligence
3 posts on threat-intelligence. Notes from public sources and my own test lab.
How BTR.sys, a Signed Driver, Becomes a Weapon
Check Point's research shows how Defender's own signed boot-time driver can be weaponized at kernel level to delete files and registry entries—a paradox of code signing that validates signatures, not intent.
August 24, 2026·4 dk readexploitnetwork-securitysecurity
5 Siemens PLC Models Targeted by AI-Powered Attacks
A joint NSA and CISA alert shows Python scripts generated with AI infiltrating S7 PLCs; how do we manage this in systems with no patch window?
August 19, 2026·2 dk readai-securityiot-securitynetwork-security
Hunting for Treasure in the IOC Trash: The ‘Real’ Face of Threat Intel
Stop chasing static IPs and hashes. If you want to actually hurt an attacker, you need to climb the Pyramid of Pain and start targeting our TTPs.
February 9, 2026·5 dk readcybersecuritypythonred-teaming