Forging security teams that pull resilience forward.

Insights

Security posts from real operations.

Playbooks, intelligence methods, and engineering patterns from teams solving difficult security problems under pressure.

RSS Feed

June 29, 2022 · MISP

MISP Purge Events Tool v0.1 Released

Operational guidance for safely purging older events in MISP, including correlation handling, benchmarks, and configuration structure.

Read Post

May 10, 2022 · MISP

MISP Auto Tagging: In Organizations We Trust

A lightweight tool for automatically adding or removing local tags on MISP events from trusted organization UUIDs.

Read Post

August 31, 2021 · Threat Intelligence · Incident Response

"Analysis of Competing Hypotheses" in Incident Response Cases

How ACH can reduce cognitive bias, structure evidence scoring, and improve confidence during cyber investigations.

Read Post

August 17, 2020 · MISP · Phishing

Phish2MISP v.1.0 released

Automating the extraction of phishing site attributes and event creation in MISP with Python tooling.

Read Post

April 7, 2020 · Detection · SOC · Metrics

MITRE ATT&CK for improved metrics and KPI on detection capabilities

How MITRE ATT&CK tactics can replace simplistic MTTD/MTTR metrics with structured, adversary-aware detection KPIs for SOC reporting.

Read Post

September 3, 2019 · MISP · Vulnerability Management

Using Threat data in your vulnerability management strategy with MISP

How to use MISP threat sharing and Metasploit CVE data to prioritize vulnerability patching based on real-world exploit activity rather than CVSS scores alone.

Read Post

Archive Preview · MISP Operations

Operationalizing MISP

Practical guidance for governance, enrichment, and cross-team adoption without workflow friction.