A 2026 walkthrough of the typical infostealer-log archive: what files it contains, what each one means, and how defenders parse them with Python and jq for downstream incident response.
A 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on: Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.
A practitioner walkthrough of building a ransomware-specific incident response runbook in 2026, combining NIST SP 800-61 r3, CISA’s #StopRansomware playbook, and the lessons from named incidents on the Ransomtracker leak feed.
A 2026 self-doxxing tutorial: run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.
A 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data: internet-scan engines, certificate transparency, and authenticated vulnerability templates.
An executive-level explainer of double extortion (the dominant ransomware playbook in 2026) covering how it works, why backups don’t fully defeat it, and the policy choices boards now have to make in the first hour of an incident.
A field guide to the 2026 initial-access-broker market: how IABs source access, how they price it, who buys, and what the listings look like under the hood.
A 2026 workflow for telling AI-generated phishing apart from real correspondence, combining email-header forensics, public LLM-detection classifiers, and DKIM/SPF replay analysis.
A practitioner’s step-by-step tutorial for hardware-key MFA in 2026. Which YubiKey to buy, how to enroll it on Google, Microsoft, GitHub, AWS, and your password manager, plus the recovery-key gotcha that locks people out.
A step-by-step tutorial for building a real home SOC with Wazuh, Suricata, and an OPNsense router on hardware that costs under $400. Endpoint EDR, network IDS, and log correlation, the same stack used by mid-market enterprises.