EDR
2 posts
Article
Count Binface breaks your correlation rule
Count Binface names a detection-pipeline attack: targeted noise injection exploits data-aggregation bias to bury true positives and poison UEBA baselines.
Article
Z3R0DAY treats unauthorised internal scanner as hostile
An internal IP is scanning ports without authorisation. How to investigate, attribute the source, and identify the inbound session that established control.