Exports Critical Registry Keys To a File The Windows Registry stores a significant amount of operating system and security information. The SAM (Security Account Manager) hive contains local account password hashes, the SYSTEM hive contains the boot key required to...
Monthly Adversary Tradecraft Spotlight – July
Potential MSTSC Shadowing Activity MSTSC shadowing is an attractive technique because it allows attackers to interact with an already authenticated user session without needing to steal credentials or create a new login event. Once an attacker has gained sufficient...
Monthly Adversary Tradecraft Spotlight – June
OpenWith.exe Executes Specified Binary This technique leverages OpenWith.exe as a proxy execution mechanism to run arbitrary code while blending in with legitimate system activity. It is a trusted Windows binary that is typically used when a user selects “Open with…”...
Monthly Adversary Tradecraft Spotlight – May 2026
Windows Recovery Environment Disabled Via Reagentc WinRE exists specifically to help users repair boot problems, restore previous system states, and troubleshoot failures when Windows can no longer start normally. Disabling the Windows Recovery Environment (WinRE) is...
The Role of AI in Cybersecurity: Smarter Defense Against Evolving Threats
Artificial intelligence is transforming cybersecurity by helping organizations detect threats faster, reduce manual workload, and improve response capabilities. As cyberattacks become more sophisticated, AI enables security teams to move from reactive defense to...
Monthly Adversary Tradecraft Spotlight – April 2026
Powershell LocalAccount Manipulation The manipulation of local user accounts with PowerShell commands (related to account management operations) can occur during legitimate administrative tasks but become suspicious when they appear unexpectedly or in an unusual...
Rethinking Detection Engineering: Black Cell’s Detection-as-Code Framework
Detection-as-Code Tools is a repository designed to standardize the creation, validation, and deployment of detection rules across multiple security platforms. Itprovides a structured, automation-ready framework that enables security engineeringteams to manage...
Monthly Adversary Tradecraft Spotlight – March 2026
PowerShell Logging Disabled Via Registry Key Tampering Disabling PowerShell logging is one of the most effective ways to reduce defender visibility during an intrusion. Attackers may inspect registry keys, test execution to see what appears in the event logs, and...
From Google Redirect to Credential Theft: A Multi-Stage Attack Analysis
Introduction Targeted attacks (APT) no longer threaten only government agencies and critical infrastructure – small and medium-sized businesses are increasingly facing sophisticated attack techniques. Job offer decoy documents, malware distributed through trusted...










