MITRE ATT&CK : Guide for Beginner In Cybersecurity
MITRE mapping is simply the practice of connecting your security alerts, detections, incidents, controls, and threat intel…
continue reading..
Defense Evasion a defender’s playbook for detection & response in Cybersecurity
1 — Execution-environment manipulation (deep dive) How it works (conceptual):Adversaries aim to run malicious code while minimizing…
continue reading..
Defense Evasion : A Beginner’s Guide in Cyber Security
Defense evasion refers to the collection of techniques adversaries use to avoid detection, bypass security controls, blend…
continue reading..
Email Header Analysis
In the digital world, email is one of the most common ways people communicate—professionally, personally, and often…
continue reading..
Why We Need Cybersecurity ? A simple explanation
In today’s world, almost everything we do is connected to technology—our work, our banking, our communication, even…
continue reading..
Privilege Escalation Checklist
Privilege Escalation is when someone gains more permissions on a system than they are supposed to have.…
continue reading..
What Windows Event IDs Do During a Cyber Attack
Role of Windows Event IDs in a Cyber Attack Windows keeps a running diary of everything that…
continue reading..
Windows Registry in Cyber Attacks
🛡️ Why the Windows Registry Matters in Cyber Attacks The Windows Registry is a central hierarchical database…
continue reading..
Microsoft Defender KQL Queries that detect common privilege-escalation behaviors
1 — High-fidelity: explorer.exe spawning suspicious children (KQL) // Explorer -> suspicious child process (high fidelity) DeviceProcessEvents…
continue reading..
