Explainers
Clear, practitioner explainers of the core security concepts: what each one is, how it actually works, and where it breaks.
Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch
A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.
Public DNS servers with filtering: a verified list of what each IP really blocks
Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.
How to Use the Wazuh API: Authenticate, Query Agents, and Automate
How to use the Wazuh API: authenticate on port 55000 for a JWT token, then query your agents and automate with copy-pasteable curl commands and a worked
How to Use Wazuh: A Practitioner's Guide to Agents, the Dashboard, and Detection
How to use Wazuh: install the server, enroll an agent, reach the dashboard, and write and test a detection rule with wazuh-logtest.
What is MITRE ATT&CK? Tactics, techniques, and how defenders actually use it
A plain-English guide to MITRE ATT&CK: what it is, how its tactics and techniques are organized, a real intrusion mapped step by step, and how defenders use it.
What is a SIEM, in plain terms (and how it differs from a SOC and EDR)
What a SIEM is, what it actually does, and how it differs from a SOC, an EDR, and plain log management - explained by a team that runs one.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.