Threat Hunting — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

RedSide Security September 17, 2026 Vulnerability 72 views

ShieldBreak (CVE-2026-69414) is a Microsoft Defender elevation-of-privilege vulnerability linked to research on bypassing mitigations for RoguePlanet (CVE-2026-50656). Explore the technical research, affected components, and defensive detection opportunities.

Continue reading: ShieldBreak: Microsoft Defender Zero-Day and Rogue…
Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

RedSide Security July 02, 2026 Tools & Technology 139 views

AnyStix is an open-source threat intelligence tool that collects country-specific malicious submissions from ANY.RUN, enriches them with indicators, converts them into STIX 2.1 format, and automatically imports them into OpenCTI. The platform enables continuous, region-focused threat intelligence collection using publicly available sandbox data.

Continue reading: Introducing AnyStix: Automated Country-Based Threa…