vivek@kali:~/blog$ grep -r "threat-intel" ./posts/

#Threat Hunting

Security research, ethical hacking tutorials, cybercrime case studies, and threat intelligence from the field.

Microsoft Launches Security Detection Report in Teams Admin Center: Impersonation, Malicious URLs & Weaponizable Files – Technical Analysis (August 2026) CVE-2026-5231
Featured · 19 min read
Microsoft has officially launched the Security Detection Report in the Teams Admin Center (Roadmap ID 560702), giving SOC teams and IT admins centralized visibility into impersonation, malicious URLs,…
Aug 11, 2026 Cyber Awareness
enterprise security Impersonation Detection KQL Malicious URL Detection
Read Full Post →
Salt Typhoon APT Analysis 2025: GhostSpider Malware, US Telecom Breach, and Threat Hunting Queries for SOC Teams CVE-2026-5190
APT Analysis
Deep technical analysis of the Salt Typhoon APT campaign that breached nine US telecom carriers and accessed CALEA…
Jul 29, 2026 11 min
CALEA Chinese APT Cisco IOS XE
Volt Typhoon Threat Hunting in 2025: KQL, Splunk, and Sigma Detection Guide for Living-Off-the-Land APT CVE-2026-5188
APT Analysis
A complete threat hunting guide for detecting Volt Typhoon living-off-the-land techniques. Includes verified KQL queries for Microsoft Sentinel,…
14 min
Chinese APT CISA advisory critical infrastructure
NightmareEclipse 2026: LegacyHive Windows 0-Day Exposed — Full Attack Chain, MDE Detection Queries & Blue Team Playbook CVE-2026-5158
Blue Team
LegacyHive is an unpatched Windows 0-day (July 2026) targeting the User Profile Service. Full technical analysis of the…
Jul 16, 2026 19 min
Blue Team CVE-2026-50656 Defender Bypass
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…
Jul 16, 2025 15 min
Blue Team Credential Dumping CVE-2021-36934