Category: Cyber Threat

How to Measure Detection Quality — precision, recall, MTTD, FP rate, SLO — metrics every detection engineer must track
0 76
Posted in Cyber Threat

How to Measure Detection Quality: Metrics Every Detection Engineer Must Track

Precision, recall, F1, alert-fatigue math, ATT&CK saturation and a working scorecard template. The metrics every detection engineer must track — with formulas and a downloadable CSV.

Living-off-the-Cloud Attack Chain Detection — CloudTrail and VPC Flow fusion for malware-free intrusions
0 103
Posted in Cyber Threat

Living-off-the-Cloud Attack-Chain Detection: CloudTrail and VPC Flow Fusion

Living off the cloud | LotC | CloudTrail | VPC Flow | fusion | malware-free

Insider Threat UEBA from VPC Flow Logs — Network-only user behaviour analytics without endpoint telemetry
0 89
Posted in Cyber Threat

Insider Threat Detection from VPC Flow Logs (UEBA Without Endpoints)

Insider threat | UEBA | identity | peer baseline | VPC Flow Logs | behavioral

Kubernetes East-West Attack Hunting from VPC Flow Logs — Pod-to-pod attack detection with namespace and service-mesh awareness
0 91
Posted in Cyber Threat

Kubernetes East-West Attack Hunting from VPC Flow Logs

Kubernetes east-west | pod-to-pod | EKS | namespace boundary | VPC Flow

Tor and Anonymizer Egress Hunting on VPC Flow Logs — Exit-node enrichment and multi-hop circuit analysis
0 92
Posted in Cyber Threat

Tor and Anonymizer Egress Hunting on VPC Flow Logs

Tor egress | anonymizer | VPN | proxy | exit node | VPC Flow Logs