Field notes from the SOC.
Practical, vendor-neutral writing on security operations, AI in the SOC, and incident response, from the team behind the Cursor Platform.
Forty Alerts, One Attack: Why Correlation Beats Alert Volume
Most security teams don't miss attacks for lack of alerts. They miss them because one intrusion arrives as dozens of disconnected signals. Here's how to turn alert volume into a single, readable attack storyline.
What an AI Security Analyst Should (and Shouldn't) Do
AI analysts are genuinely useful for the first shift of security work, if they come with the right guardrails. A practical guide to where AI helps, where it must not act alone, and what to ask before you switch one on.
Reversible Response: Build Rollback Into Your Ransomware Plan
Containment stops ransomware from spreading, but recovery decides what it costs you. How to design a reversible response plan that pairs fast isolation with endpoint rollback, immutable backups, and identity resets.