Resources Blog

Detecting Microsoft Outlook Vulnerability CVE-2023-23397 in Splunk and IBM QRadar

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps, Detection Posture Management

Posted by Tamir Oren Bar-Hai and Phil Neray on March 20, 2023

Summary Discovered by the Ukrainian CERT and attributed to APT28 (aka Fancy Bear or Strontium, the Russian GRU threat actor), CVE-2023-23397 is being actively exploited in targeted attacks against gov... Read More>>

CardinalOps CEO Discusses the State of Today's SOC Teams on Silo Busting Podcast

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on March 14, 2023

Michael Mumcuoglu, CEO and Founder of CardinalOps, recently join the EPAM Continuum podcast, Silo Busting, for a discussion assessing the state of today’s SOC teams. Also featured on the podcast were ... Read More>>

State of Identity Podcast Episode 320: Detection Posture Management

Topics: Featured, Security Engineering, MITRE ATT&CK, SecOps, Detection Posture Management

Posted by Phil Neray on March 10, 2023

Recently Phil Neray, VP of Cyber Defense Strategy at CardinalOps, was invited to join the State of Identity Podcast for a conversation on the latest cybersecurity threats and why orchestration is the ... Read More>>

CardinalOps Named as Winner in 2023 Cybersecurity Excellence Awards for Detection Posture Management

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on March 9, 2023

TEL-AVIV, Israel and BOSTON, March 9, 2023 -- CardinalOps, the detection posture management company, today announced that the 2023 Cybersecurity Excellence Awards have selected the CardinalOps platfor... Read More>>

How Detection Posture Management Can Help CISOs Track the Right Metrics

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on March 1, 2023

In a recent SC Media column, Michael Mumcuoglu - CEO of CardinalOps, writes that instead of manually identifying gaps in MITRE ATT&CK coverage, it should be automated so that security teams always... Read More>>

What CISOs Don’t Know About Their SOCs

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on January 12, 2023

In a recent SC Media column, Michael Mumcuoglu - CEO of CardinalOps, wrote how continuous improvement techniques can help CISOs more effectively manage the growing threat landscape and improve the vis... Read More>>

Why MITRE ATT&CK Has Taken Over the SOC World

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on August 17, 2022

I recently listened to an excellent summary about why MITRE ATT&CK has taken over the SOC world (sorry, it's behind a paywall called "CSO Perspectives," but this blog post is intended to summarize... Read More>>

Leveraging AI and Automation with MITRE ATT&CK to Eliminate Detection Coverage Gaps in Your SOC

Topics: News, Featured, Threat Management, Security Engineering, MITRE ATT&CK, SecOps

Posted by Phil Neray on August 15, 2022

At Black Hat 2022, our VP of Cyber Defense Strategy was interviewed on Security Guy TV to discuss why MITRE ATT&CK has become a standard way of describing your defensive posture to management as w... Read More>>

SIEM Detections for Okta PassBleed (Splunk, Microsoft Sentinel, IBM QRadar, Sumo Logic)

Topics: News, Featured, Threat Management, MITRE ATT&CK, SecOps

Posted by Liran Ravich and Phil Neray on July 26, 2022

Summary This blog post summarizes new password stealing and impersonation risks recently discovered for Okta, along with recommended SIEM detection rules and associated MITRE ATT&CK techniques for... Read More>>

Splunk and other SIEM detections for Follina, a clever MS-Office 0-day

Topics: News, Featured, Threat Management, MITRE ATT&CK, SecOps

Posted by Liran Ravich on June 1, 2022

Summary This blog post summarizes Follina, an RCE zero-day discovered in Microsoft Office. It provides recommended detections in the native query languages for Splunk, Microsoft Sentinel, IBM QRadar, ... Read More>>