Exports Critical Registry Keys To a File The Windows Registry stores a significant amount of operating system and security information. The SAM (Security Account Manager) hive contains local account password hashes, the SYSTEM hive contains the boot key required to...
Monthly Adversary Tradecraft Spotlight – July
Potential MSTSC Shadowing Activity MSTSC shadowing is an attractive technique because it allows attackers to interact with an already authenticated user session without needing to steal credentials or create a new login event. Once an attacker has gained sufficient...
Monthly Adversary Tradecraft Spotlight – June
OpenWith.exe Executes Specified Binary This technique leverages OpenWith.exe as a proxy execution mechanism to run arbitrary code while blending in with legitimate system activity. It is a trusted Windows binary that is typically used when a user selects “Open with…”...
Monthly Adversary Tradecraft Spotlight – May 2026
Windows Recovery Environment Disabled Via Reagentc WinRE exists specifically to help users repair boot problems, restore previous system states, and troubleshoot failures when Windows can no longer start normally. Disabling the Windows Recovery Environment (WinRE) is...
Monthly Adversary Tradecraft Spotlight – April 2026
Powershell LocalAccount Manipulation The manipulation of local user accounts with PowerShell commands (related to account management operations) can occur during legitimate administrative tasks but become suspicious when they appear unexpectedly or in an unusual...
Rethinking Detection Engineering: Black Cell’s Detection-as-Code Framework
Detection-as-Code Tools is a repository designed to standardize the creation, validation, and deployment of detection rules across multiple security platforms. Itprovides a structured, automation-ready framework that enables security engineeringteams to manage...
Escape the Security Hamster Wheel: How Detection-as-Code Sets SOC Teams Free
Tired of chasing alerts and feeling like you're constantly one step behind attackers? In today's threat landscape, traditional security operations are like running on a hamster wheel – exhausting and ultimately ineffective. SOC teams are drowning in alerts, struggling...








