Threat Intel Versus Threat Hunting, What’s the Difference?

MITRE ATT&CK Matrix – C2 Connection Proxy

Identifying Long Connections with Bro/Zeek

MITRE ATT&CK HTTPS

Log Analysis Part 3 – Lateral Movement

Log Analysis Part 2 – Detecting Host Attacks: Or, How I Found and Fell in Love with DeepBlueCLI

Log Analysis Part 1 – Enterprise Logging Approaches

Detecting Compromises With AI-Hunter

Passer, a Passive Sniffer and Inventory Tool