Writing

77 posts since 2020. Notes on blue teaming, detection engineering, SIEM/SOAR and incident response.

Featured

  1. 01MCP and SIEM Integration: Log Poisoning and Indirect Prompt Injection (Part 2)The second part of the series looks at the risk that comes from the source of the data entering the SIEM. It covers how an attacker can steer a language model with nothing but a log line, which patterns actually work and a detection rule.11 min read
  2. 02MCP and SIEM Integration: Permission Surface Analysis on Splunk (Part 1)In this article we look at the MCP (Model Context Protocol) and Splunk integration from a security point of view. It covers the setup steps, the permission surface of the tools the server exposes and the precautions worth taking.14 min read
  3. 03Malware Distribution Techniques Using LNK FilesIn this article, we'll go step by step through how malware can be distributed using LNK files. In particular, we'll look at how malicious commands can be embedded…4 min read

20262

20242

20236

202210

202138

202019