Topic · 6 articles
SOC Operations
Detection engineering, telemetry, and wiring storage into SIEM and SOAR.
Spans Threat Brief, Practitioner Guide, RackTop Perspective and Cyberstorage Explainer.

No malware, no lateral movement, and every document copied anyway
A phone call to an executive, a stolen session token, and a bulk sweep of SharePoint, OneDrive, Exchange, and Box. Researchers found no malware and no lateral movement in the campaign, which leaves the reads as the only thing left to detect.
7 min read

Medusa’s update: the theft was throttled to stay under your thresholds
The updated federal Medusa advisory publishes the commands affiliates run to find file shares and copy documents off them, including a rate limiter tuned to sit under volume alerts.
6 min read

NAS ransomware protection: catch the attack by how it behaves
Real NAS ransomware protection is not a signature list or a nightly backup. It is user behavior analytics on every file operation, active defense that terminates a hostile session in under a second, and a cybervault that survives even administrative compromise.
5 min read

Your security stack watches everything except the data
Endpoints, networks, identities, email, cloud posture: modern security programs instrument all of it. The one thing almost nobody instruments is the file data attackers are actually after.
5 min read

Ransomware protection at the storage layer: how it actually works
What real ransomware protection looks like at the layer attacks actually touch: the visibility, detection, policy, response, recovery, and evidence chain, explained link by link.
9 min read

File activity telemetry: what your SOC actually needs from storage
Most NAS audit feeds were designed for compliance checkboxes, not threat detection. Here is what detection-grade file activity telemetry looks like, how to wire it into SIEM and SOAR workflows without drowning the license, and the two tests that prove the integration is real.
5 min read
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.
