Hidden Cursor Blog

Field notes from the SOC.

Practical, vendor-neutral writing on security operations, AI in the SOC, and incident response, from the team behind the Cursor Platform.

Security Operations

Forty Alerts, One Attack: Why Correlation Beats Alert Volume

Most security teams don't miss attacks for lack of alerts. They miss them because one intrusion arrives as dozens of disconnected signals. Here's how to turn alert volume into a single, readable attack storyline.

· 4 min read
AI in Security

What an AI Security Analyst Should (and Shouldn't) Do

AI analysts are genuinely useful for the first shift of security work, if they come with the right guardrails. A practical guide to where AI helps, where it must not act alone, and what to ask before you switch one on.

· 4 min read
Incident Response

Reversible Response: Build Rollback Into Your Ransomware Plan

Containment stops ransomware from spreading, but recovery decides what it costs you. How to design a reversible response plan that pairs fast isolation with endpoint rollback, immutable backups, and identity resets.

· 4 min read