This Microsoft Defender for Endpoint ASR rule is really strong:
Block executable files from running unless they meet a prevalence, age, or trusted list criterion
Why is there no equivalent with other EDR products?
Our new website is live: https://t.co/eSjzqmwhvx
Since 2017 we have done one thing: vulnerability research and exploit development.
19 research articles · 1,657 pages · free
22 technical courses across 5 tracks
Original Research. Reliable Exploitation.
I always look forward to when we, CISA’s red team, gets to publish our reports, and today is one of those days! “A Tale of Two SOCs” - a story where we targeted two different orgs, with the same tradecraft, and very different responses. Read it! - https://t.co/vTldiRTi7J
Free Linux resources that actually taught me the fundamentals. No paid courses needed.
Beginner:
1. https://t.co/cDL7hONKP6 — best free visual Linux learning site
2. https://t.co/vk3jphNqMp — learn Linux by hacking. Addictive.
3. https://t.co/QAHMJhkXjy — paste any command, it explains every part
Intermediate:
1. https://t.co/diFHopj5Ox — short, practical man pages. Way more useful than man.
2. https://t.co/Dh1lzQhFaG — MIT course on tools every dev needs. Free.
3. youtube: LearnLinuxTV — practical, no fluff
Advanced:
1. https://t.co/ifOyr2uP8v — Brendan Gregg's blog on Linux performance. Elite level.
2. https://t.co/8hGBTSI8XJ — full man pages when you need the real detail
3. https://t.co/NVXbhpZp2T — when you want to go very deep
🚨 BREAKING: Someone just built the exact tool Andrej Karpathy said someone should build.
48 hours after Karpathy posted his LLM Knowledge Bases workflow, this showed up on GitHub.
It's called Graphify. One command. Any folder. Full knowledge graph.
Point it at any folder. Run /graphify inside Claude Code. Walk away.
Here is what comes out the other side:
-> A navigable knowledge graph of everything in that folder
-> An Obsidian vault with backlinked articles
-> A wiki that starts at index. md and maps every concept cluster
-> Plain English Q&A over your entire codebase or research folder
You can ask it things like:
"What calls this function?"
"What connects these two concepts?"
"What are the most important nodes in this project?"
No vector database. No setup. No config files.
The token efficiency number is what got me:
71.5x fewer tokens per query compared to reading raw files.
That is not a small improvement. That is a completely different paradigm for how AI agents reason over large codebases.
What it supports:
-> Code in 13 programming languages
-> PDFs
-> Images via Claude Vision
-> Markdown files
Install in one line:
pip install graphify && graphify install
Then type /graphify in Claude Code and point it at anything.
Karpathy asked. Someone delivered in 48 hours.
That is the pace of 2026.
Open Source. Free.
I'm literally begging people to start collecting, curating, and reading RSS feeds to get a good pulse in what's going on in the industry. There is no better concentrated source of information than a well curated RSS feed.
Most SOC reports and write-ups are punchy, to-the-point, polished reports. After all, every investigation (regardless of vertical) starts out as a chaotic mix of different threads that we corral into order like a tired sheepdog dreaming of making it as an internet meme and retiring on the royalties.
Unfortunately, these polished reports don't capture how we actually form our suspicions, the pivots, the dead ends, the moment it all starts to make some semblance of sense.
If you've ever wondered what that process actually looks like, I've spun up a blog series that breaks down real MDR incidents to capture what it's like riding the investigation roller-coaster, so those new to the industry can see how we progress from start to end within the context of a SOC investigation.
Please enjoy this breakdown of a threat actor's attempt to enumerate and pivot further into the victim's environment — made with 100% organic human analyst tears! https://t.co/quNqiPaTDl
Have you ever seen a CVE and want to turn it into an exploit but don't know how? Check out my latest tutorial where I turn CVE-2018-1160 into a fully functioning exploit!
Video can be found here:
https://t.co/VMtvy4U8ov
It’s time to lock in. If you’re struggling with bug bounties, spend the next few weeks finding a target you personally enjoy. Bigger the scope the better! Then focus on them everyday for the entire year. Aim to hack 2-3 hours minimum a day. You’ll learn lots and find bugs.
GL!
Is Remote Code Execution the same as Remote Command Execution? It’s a trick question, and a common point of confusion for anyone new to cybersecurity.
We’ve all been there, staring at a list of terms that seem identical:
• Remote Code Execution
• Remote Command Execution
• Code Injection
• Command Injection
• RCE
I've spent enough time explaining this to others that I finally broke it all down. Let's make it simple.👇
Our next 'Pathway to VR' profile comes from Adam, a researcher in our Basebands team.
Like many researchers, Adam honed his hacking skills by taking part in CTFs. He gives some great insights about the need for perseverance and continual curiosity in VR.