Resources
Analysis from the people building it
Analysis of AI SOC evaluation, alert triage, deployment sovereignty and the compliance verbs regulators actually use. Written by the people building the platform, which means it is opinionated and occasionally inconvenient for us.
Archive
Everything else
10 August 2026
Nobody Asked It to Hack Anything: An AI Agent, a Gym Booking API, and the End of Intent-Based Triage
A Melbourne man asked his personal AI agent to move him up a gym waitlist. It found two API flaws and canceled a stranger's reservation. The vulnerabilities were…
Read9 August 2026
The HIPAA Requirement Nobody at a Small Practice Actually Performs: Information System Activity Review
HIPAA's Security Rule, 45 CFR ยง164.308(a)(1)(ii)(D), requires regular review of system activity logs. It is required, not addressable. For small behavioral health…
Read9 August 2026
The CMMC Pause Didn't Pause Your Obligations: What NIST 800-171 Still Requires of Small Defense Subcontractors
CMMC Phase 2 is suspended pending a reform review due mid-September 2026, but DFARS 252.204-7012, SPRS self-assessments, and NIST SP 800-171 remain fully in force. With…
Read9 August 2026
Reg S-P Is Now Fully in Force: Why "We Have a Compliance Consultant" No Longer Covers Your RIA
As of June 3, 2026, the SEC's amended Regulation S-P applies to every RIA, including smaller firms. A written incident response program and 30-day customer notification…
Read9 August 2026
Your Escrow Account Is the Target: Wire Fraud, ALTA Pillar 3, and What Title Agencies Are Expected to Monitor
BEC losses hit $3.04 billion in 2025, and home closings are a favorite target. What ALTA Best Practices Pillar 3 and your underwriter actually expect a title agency's…
Read5 August 2026
Signed, Verified, Poisoned: The npm Worm That Weaponized Developer AI Agents
On August 4, 2026, a self-propagating npm worm poisoned hundreds of packages in under four hours, and shipped hooks that execute the moment a developer opens the repo in…
Read17 July 2026
14 Mega-Breaches, Three Playbooks: How ShinyHunters Dominated H1 2026
ShinyHunters is the top threat actor of H1 2026, linked to 14 of the largest confirmed breaches. Analysis of the three attack playbooks: voice phishing, cloud…
Read14 July 2026
The Front Door Was Open: How a VPN Zero-Day Gave Qilin Ransomware Unauthenticated Access
CVE-2026-50751 (CVSS 9.3): a logic flaw in Check Point Remote Access VPN IKEv1 certificate validation gives unauthenticated attackers remote access. Analysis of the…
Read11 July 2026
When Exploits Arrive Before Patches: The 24-Hour Window Defenders Are Losing
AI-enabled attacks surged 89% year-over-year per CrowdStrike's 2026 Global Threat Report, with 28.3% of CVEs exploited within 24 hours of disclosure. Analysis of how AI…
Read11 July 2026
Talking Through the Walls: How DragonForce Ransomware Hides C2 Inside Microsoft Teams Infrastructure
DragonForce deploys the first malware using Microsoft Teams TURN relay for command-and-control. Analysis of how Backdoor.Turn exploits trusted infrastructure to make C2…
Read16 April 2026
Living in the Walls: Why Volt Typhoon and Salt Typhoon Dwell in Critical Infrastructure for Years
Chinese state-sponsored APTs Volt Typhoon and Salt Typhoon have spent up to five years inside US critical infrastructure and every major US telecom. An analysis of why…
Read6 April 2026
The 2026 Ransomware Surge: Why Hospitals, Cities, and Critical Infrastructure Can't Respond Fast Enough
Ransomware attacks are shutting down trauma centers, paralyzing city governments, and disrupting medical supply chains. An analysis of the 2026 ransomware surge and why…
Read30 March 2026
SIEM vs SOAR vs XDR vs AI SOC: What's the Difference?
A vendor-neutral comparison of SIEM, SOAR, XDR, and AI SOC platforms. Understand what each security operations technology does, where they overlap, and how to choose the…
Read25 March 2025
How One Hacker Used AI to Breach an Entire Government
A single hacker used a consumer AI chatbot to breach 9 Mexican government agencies and steal 150GB of sensitive data, including 195 million taxpayer records. Here's what…
Read25 March 2025
The AI SOC Buyer's Guide
A comprehensive buyer's guide for evaluating AI-powered SOC platforms. Covers agent architecture, alert processing depth, deployment models, compliance, SOAR…
Read25 March 2025
Air-Gapped AI: Securing Classified Environments
How Intruex delivers the same AI-powered security operations in fully disconnected, air-gapped networks using self-hosted LLMs and local inference, no cloud dependency…
Read25 March 2025
How Attack Narrative Correlation Works
SOC teams receive thousands of alerts daily, but isolated alerts don't tell a story. Learn how attack narrative correlation transforms fragmented signals into complete…
ReadReference
The pages an evaluator usually wants
How a verdict is made
The full pipeline, both investigation tiers, and how a verdict is produced.
Trust & audit
Decision replay, tenant isolation, approval gates and how every figure is sourced.
Deployment
Three tiers, scoped individually, with the RFP questions answered in advance.
The analyst team
Who handles what, and how routing decides which specialist reads an alert.
Integrations
Native connectors for common sources and a universal OCSF path for everything else.
API trial
Send an alert as JSON and read the disposition, confidence and reasoning back.
Bring us an alert you already know the answer to
Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.
