vivek@kali:~/blog$ grep -r "threat-intel" ./posts/

#KQL Queries

Security research, ethical hacking tutorials, cybercrime case studies, and threat intelligence from the field.

Volt Typhoon Threat Hunting in 2025: KQL, Splunk, and Sigma Detection Guide for Living-Off-the-Land APT CVE-2026-5188
Featured · 14 min read
A complete threat hunting guide for detecting Volt Typhoon living-off-the-land techniques. Includes verified KQL queries for Microsoft Sentinel, Splunk SPL for Sysmon, three production-ready Sigma rules, MITRE ATT&CK…
Jul 29, 2026 APT Analysis
Chinese APT CISA advisory critical infrastructure KQL Queries
Read Full Post →
NightmareEclipse 2026: LegacyHive Windows 0-Day Exposed — Full Attack Chain, MDE Detection Queries & Blue Team Playbook CVE-2026-5158
Blue Team
LegacyHive is an unpatched Windows 0-day (July 2026) targeting the User Profile Service. Full technical analysis of the…
Jul 16, 2026 19 min
Blue Team CVE-2026-50656 Defender Bypass
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…
Jul 16, 2025 15 min
Blue Team Credential Dumping CVE-2021-36934