<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Hatem Sayed — Insights</title>
    <link>https://s3cg33k.com</link>
    <description>Cybersecurity • DFIR • Threat Hunting</description>
    <language>en</language>
    <item>
      <title><![CDATA[Velociraptor: Fleet-Wide Hunting and Remote Triage at Scale]]></title>
      <link>https://s3cg33k.com/blog/2026-06-18-velociraptor-fleet-hunting</link>
      <guid>https://s3cg33k.com/blog/2026-06-18-velociraptor-fleet-hunting</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[When you need the same forensic question answered across thousands of endpoints in minutes, Velociraptor is the tool I reach for. A practical tour of artifacts, hunts, VQL, and the offline collector.]]></description>
    </item>

    <item>
      <title><![CDATA[Putting an LLM in the Triage Loop — Usefully, and Safely]]></title>
      <link>https://s3cg33k.com/blog/2026-06-10-llms-in-dfir-triage</link>
      <guid>https://s3cg33k.com/blog/2026-06-10-llms-in-dfir-triage</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[LLMs are genuinely useful in DFIR — for summarising, drafting queries, and explaining code. They are also confidently wrong and leak whatever you feed them. Here is where they earn their place in the workflow, and the two rules I never break.]]></description>
    </item>

    <item>
      <title><![CDATA[Investigating Identity Attacks in Microsoft 365 and Azure]]></title>
      <link>https://s3cg33k.com/blog/2026-05-20-m365-azure-identity-forensics</link>
      <guid>https://s3cg33k.com/blog/2026-05-20-m365-azure-identity-forensics</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The modern intrusion is identity-first. A practical guide to the logs and queries that expose illicit OAuth consent, token theft, and post-compromise persistence in M365 and Entra ID.]]></description>
    </item>

    <item>
      <title><![CDATA[Deepfakes and AI-Assisted Fraud: What Changes for Defenders]]></title>
      <link>https://s3cg33k.com/blog/2026-04-07-deepfake-bec-ai-fraud</link>
      <guid>https://s3cg33k.com/blog/2026-04-07-deepfake-bec-ai-fraud</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Generative AI didn't invent business email compromise — it removed its tells and added a face and a voice. The defence isn't better deepfake detection; it's process that doesn't trust a face or a voice in the first place.]]></description>
    </item>

    <item>
      <title><![CDATA[Chainsaw + Sigma: High-Signal Hunts to Run Every Week]]></title>
      <link>https://s3cg33k.com/blog/2026-03-10-chainsaw-sigma-detections</link>
      <guid>https://s3cg33k.com/blog/2026-03-10-chainsaw-sigma-detections</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A compact, automatable set of Sigma hunts that Chainsaw can sweep across EVTX in minutes — covering the behaviours that actually show up in real intrusions.]]></description>
    </item>

    <item>
      <title><![CDATA[Detection-as-Code: Putting Sigma Under CI/CD]]></title>
      <link>https://s3cg33k.com/blog/2026-02-16-detection-as-code-sigma</link>
      <guid>https://s3cg33k.com/blog/2026-02-16-detection-as-code-sigma</guid>
      <pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A detection you can't version, test, or measure is a liability. Treating Sigma rules like source code — linted, unit-tested against real samples, and deployed by pipeline — is how detection engineering grows up.]]></description>
    </item>

    <item>
      <title><![CDATA[Reconstructing Execution with the $MFT and USN Journal]]></title>
      <link>https://s3cg33k.com/blog/2026-01-28-mft-usn-execution-timeline</link>
      <guid>https://s3cg33k.com/blog/2026-01-28-mft-usn-execution-timeline</guid>
      <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[When an attacker timestomps and deletes, NTFS metadata still tells the story. Using the $MFT, $UsnJrnl, and execution artefacts to rebuild what ran and when.]]></description>
    </item>

    <item>
      <title><![CDATA[AiTM Phishing: Catching the Session Theft MFA Can't Stop]]></title>
      <link>https://s3cg33k.com/blog/2025-12-09-aitm-session-theft-detection</link>
      <guid>https://s3cg33k.com/blog/2025-12-09-aitm-session-theft-detection</guid>
      <pubDate>Tue, 09 Dec 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[Adversary-in-the-middle kits don't break your MFA — they wait for you to complete it, then steal the session. Here is how the token theft actually looks in Entra sign-in logs, and how to evict it.]]></description>
    </item>

    <item>
      <title><![CDATA[When There's Nothing to Decrypt: Responding to Encryption-less Extortion]]></title>
      <link>https://s3cg33k.com/blog/2025-11-12-encryptionless-extortion-response</link>
      <guid>https://s3cg33k.com/blog/2025-11-12-encryptionless-extortion-response</guid>
      <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[More than half of extortion cases now skip encryption entirely — the leverage is the stolen data. That changes the whole response: there is nothing to restore, so the case lives or dies on reconstructing exactly what left the building.]]></description>
    </item>

    <item>
      <title><![CDATA[PowerShell Incident Triage: From a 4104 to Root Cause]]></title>
      <link>https://s3cg33k.com/blog/2025-09-15-powershell-triage-4104-to-rca</link>
      <guid>https://s3cg33k.com/blog/2025-09-15-powershell-triage-4104-to-rca</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[A fast, repeatable path from a single Script Block (4104) event to decoded payload, persistence, scope, and a defensible root-cause narrative.]]></description>
    </item>

    <item>
      <title><![CDATA[Lessons from the Frontlines: Hunting What the Alerts Miss]]></title>
      <link>https://s3cg33k.com/blog/2025-09-15-threat-hunting</link>
      <guid>https://s3cg33k.com/blog/2025-09-15-threat-hunting</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[Why the highest-impact findings come from hypothesis-driven hunts and correlated forensic artefacts — not the alert queue — illustrated with a real ICMP-beaconing case.]]></description>
    </item>

    <item>
      <title><![CDATA[Memory Forensics 101: A Practical Volatility 3 Playbook]]></title>
      <link>https://s3cg33k.com/blog/2025-09-15-volatility3-playbook</link>
      <guid>https://s3cg33k.com/blog/2025-09-15-volatility3-playbook</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[A field-tested Volatility 3 sequence that gets you from a raw dump to injected code, process hollowing, and live C2 artefacts — fast.]]></description>
    </item>

    <item>
      <title><![CDATA[Build a DFIR Lab: Windows 11 + SIFT]]></title>
      <link>https://s3cg33k.com/blog/2025-09-15-windows11-sift-lab</link>
      <guid>https://s3cg33k.com/blog/2025-09-15-windows11-sift-lab</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[A pragmatic, repeatable lab for investigations — images, logs, memory, and timelines — with a structure that keeps evidence clean and the first hour productive.]]></description>
    </item>

    <item>
      <title><![CDATA[From Alerts to Answers: Building Hunt Playbooks]]></title>
      <link>https://s3cg33k.com/blog/2025-09-12-hunt-playbooks-from-alerts-to-answers</link>
      <guid>https://s3cg33k.com/blog/2025-09-12-hunt-playbooks-from-alerts-to-answers</guid>
      <pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[Turning ad-hoc hunts into reusable, hypothesis-driven playbooks mapped to ATT&CK — with KPIs that prove they earn their place.]]></description>
    </item>

    <item>
      <title><![CDATA[Deobfuscating Malicious PowerShell at Scale]]></title>
      <link>https://s3cg33k.com/blog/2025-09-10-deobfuscating-malicious-powershell</link>
      <guid>https://s3cg33k.com/blog/2025-09-10-deobfuscating-malicious-powershell</guid>
      <pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[A repeatable workflow for recovering and decoding obfuscated PowerShell from Operational logs — script-block reconstruction, layered-obfuscation tells, and host pivots through process lineage.]]></description>
    </item>

    <item>
      <title><![CDATA[Building Intel-Driven Detections Mapped to ATT&CK]]></title>
      <link>https://s3cg33k.com/blog/intel-driven-detections</link>
      <guid>https://s3cg33k.com/blog/intel-driven-detections</guid>
      <pubDate>Fri, 22 Aug 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[How to turn raw indicators into durable, low-noise detections that survive an actor swapping infrastructure — by detecting behaviour, not just IOCs.]]></description>
    </item>
  </channel>
</rss>