<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection on CuraSec</title><link>https://curasec.metacog.co.kr/tags/detection/</link><description>Recent content in Detection on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 25 Aug 2026 11:39:54 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/detection/index.xml" rel="self" type="application/rss+xml"/><item><title>Unit 42: State of AI-Enabled Malware August 2026 Report</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-the-state-of-ai-enabled-malware-august-2026-from-brand-abuse/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-the-state-of-ai-enabled-malware-august-2026-from-brand-abuse/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research on AI-authored malware and agentic execution techniques is worth reviewing to understand how these threats interact with build/CI environments, but no exploited CVEs or supply-chain IOCs are present requiring immediate action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Unit 42&amp;rsquo;s analysis of AI-enabled malware TTPs — including brand abuse lures and agentic execution chains — is worth translating into behavioral detection tuning this quarter; review the report for any new evasion patterns to add to endpoint analytics rules.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This report provides useful benchmarking data on the maturation of AI-assisted threats, suitable for future board deck context on the AI threat landscape, but requires no immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>PowerShell guide for auditing Entra ID login logs and detecting password sprays</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-even-moar-powershell-looking-at-entra-logins-the-good-the-ba/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-even-moar-powershell-looking-at-entra-logins-the-good-the-ba/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical reminder that cloud identity login logs (Entra ID sign-in logs) deserve the same daily scrutiny as on-prem logs; useful if you haven&amp;rsquo;t wired these into a monitoring workflow yet, but no patch or config change required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Adopt or adapt the PowerShell queries shown to pull Entra successful/failed login data for routine password-spray hunting; worth scheduling as a log-source coverage improvement if Entra sign-in logs aren&amp;rsquo;t already feeding your SIEM.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>AI-Powered Phishing Renders Domain Blocklists Obsolete</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-how-ai-powered-phishing-killed-blocklists-for-good/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-how-ai-powered-phishing-killed-blocklists-for-good/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Browser-level, technique-based phishing detection is a useful design principle to evaluate when assessing IdP or SSO defenses, but no specific CVE or configuration change is required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Evaluate whether current phishing detections rely heavily on domain blocklists and investigate adding technique-based behavioral signals (e.g., credential-harvest page patterns) to supplement IOC-driven coverage.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful framing for a board conversation about why threat intelligence investments have diminishing returns against AI-assisted phishing — relevant for future budget and vendor evaluation discussions.&lt;/li>
&lt;/ul></description></item><item><title>Automated SSH Attacks Achieve Persistence in ~22 Seconds</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-22-seconds-to-compromise-how-automated-ssh-actors-move-from/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-22-seconds-to-compromise-how-automated-ssh-actors-move-from/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research on automated SSH attack timelines underscores why key-only auth, login alerting, and session monitoring must be in place before an attacker lands — no specific patch needed, but validates hardening posture on any SSH-exposed host.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The ~22-second login-to-persistence window is a concrete benchmark: review SSH authentication alert latency in your SIEM and ensure post-login activity (new cron jobs, authorized_keys writes, shell spawns) triggers faster than that window closes.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Unit 42: ~50% of C2 Malware Bypasses DNS via Direct-IP Connections</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-almost-half-of-malware-samples-communicate-direct-to-ip/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-almost-half-of-malware-samples-communicate-direct-to-ip/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit egress firewall rules to block or alert on outbound connections to raw IPs (not resolved via internal DNS); this is a concrete hardening step supported by the finding.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for outbound traffic to bare IP addresses without preceding DNS resolution — this pattern is a high-signal C2 indicator worth adding to your SIEM hunting queries.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>