# Kraven Security > Helping demystify cyber threat intelligence for businesses and individuals ## Posts - [Courses of Action Matrix: The Must-Know Actions for Cyber Security](https://kravensecurity.com/the-courses-of-action-matrix/): Discover the must-know cyber security actions you can take to defend your business from the latest threats by unpacking the courses of actions (CoA) matrix. - [Triaging the Week 012](https://kravensecurity.com/triaging-the-week-012/): Big bounty offered for ransomware leaders, malware gets more sophisticated, and a critical vulnerability in Zoom in triaging the week 012. - [Netlas.io: A Powerful Suite of Tools for Threat Hunting](https://kravensecurity.com/threat-hunting-with-netlas-io/): Discover netlas.io, a powerful suite of tools to enrich your threat hunts, add threat intelligence to your investigations, Discover netlas.io, a powerful suite of tools to enrich your threat hunts, add threat intelligence to your investigations, and map your attack surface. - [Triaging the Week 011](https://kravensecurity.com/triaging-the-week-011/): New container escape, malware spreads with Facebook ads, and toothbrushes fight back in triaging the week 011. - [Top 5 Cyber Threat Intelligence Lifecycle Challenges in 2025](https://kravensecurity.com/top-5-cyber-threat-intelligence-lifecycle-challenges/): Discover the top 5 real-world threat intelligence lifecycle challenges you will face and how to overcome them to produce actionable intelligence. - [Triaging the Week 010](https://kravensecurity.com/triaging-the-week-010/): NSA steals data, Mercedes fumbles GitHub tokens, and the police hit the Bitcoin jackpot in triaging the week 010. - [Malware Configuration Parsers: An Essential Hunting Tool](https://kravensecurity.com/malware-configuration-parsers/): Learn why malware configuration parsing is an essential skill for any threat hunter, plus how to use a malware configuration parsers to do this automatically. - [Triaging the Week 009](https://kravensecurity.com/triaging-the-week-009/): Malware abuses Discord, Australia imposes sanctions, and the Uber of cybercrime is revealed in triaging the week 009. - [Discover MITRE’s CTI Blueprints: A Revolutionary New Project](https://kravensecurity.com/mitre-cti-blueprints/): Learn about MITRE’s CTI Blueprints project. A revolutionary new CTI project that aims to help analysts deliver high-quality, standardized CTI reports. - [Triaging the Week 008](https://kravensecurity.com/triaging-the-week-008/): New mitigations and with GrapheneOS and iShutdown scripts, top ransomware gangs to watch out for in 2024, and MacOS malware evades XProtect in triaging the week 008. - [What Is the Indicator Lifecycle? A Guide to Using Indicators in 2026](https://kravensecurity.com/what-is-the-indicator-lifecycle/): Learn the 3-stage indicator lifecycle, a model for turning raw data into actionable cyber threat intelligence for proactive defense and threat hunting. - [Triaging the Week 007](https://kravensecurity.com/triaging-the-week-007/): DPKR steals all the crypto, X accounts are under siege, and China Cracks Apple’s AirDrop in triaging the week 007. - [Getting Started With Intelligence Requirements: A Full Guide](https://kravensecurity.com/what-are-intelligence-requirements/): Discover how to create cyber threat intelligence requirements that help align your business objectives with your threat intelligence team's output. - [Triaging the Week 006](https://kravensecurity.com/triaging-the-week-006/): Australian court hacked, a formal ban on ransomware incoming, and Mandiant X account hijacked in triaging the week 006. - [The Threat Intelligence Lifecycle: Streamline Your CTI Operations](https://kravensecurity.com/the-threat-intelligence-lifecycle/): Discover the cyber threat intelligence lifecycle in this comprehensive guide. Learn the 6 stages of the lifecycle and how to apply them to your CTI operations. - [Triaging the Week 005](https://kravensecurity.com/triaging-the-week-005/): Hackers abuse GitHub, FBI takes major shot at ALPHV ransomware, and the Lapsus$ hacker gets sentenced in triaging the week 005. - [Cyber Threat Intelligence 101: Everything you Need to Know](https://kravensecurity.com/what-is-cyber-threat-intelligence-a-quick-guide/): A definitive guide to cyber threat intelligence. Learn what cyber threat intelligence is and how it is used for proactive defense against the latest threats. - [Triaging the Week 004](https://kravensecurity.com/triaging-the-week-004/): DNS vulnerabilities, cloud engineers rampage, and the UK at risk of catastrophic ransomware attack in triaging the week 004. - [The Importance of Clear Definitions in Threat Intelligence](https://kravensecurity.com/the-importance-of-clear-definitions-in-threat-intelligence/): Discover why it is important to have clear definitions for key cyber threat intelligence concepts and how this series can be your reference guide. - [Triaging the Week 003](https://kravensecurity.com/triaging-the-week-003/): Google Workspace vulnerabilities, a new version of Kali Linux, and Kraven Security’s website is now live in triaging the week 003. - [Kraven Security Website Launch!](https://kravensecurity.com/kraven-security-website-launch/): We have officially launched the website. This interactive platform lets you learn all things cyber threat intelligence, threat hunting, and custom tooling. - [Triaging the Week 002](https://kravensecurity.com/triaging-the-week-002/): China Influencers on the Rise, Space Agencies Under Attack, and Advent of Cyber 2023 Begins in triaging the week 002. - [Discover the Ultimate Cyber Security Notetaking App: Polarity](https://kravensecurity.com/the-ultimate-cybersecurity-notetaking-app-polarity/): Discover the new cyber security notetaking app that integrates with your organization’s tools and is an effective copilot for all your investigations. - [Triaging the Week 001](https://kravensecurity.com/triaging-the-week-001/): OpenAI turmoil, COO hacks hospital to boost sales, and Kraven Security starts a newsletter in triaging the week 001. - [Python Threat Hunting Tools: Part 12 - MISP and CrowdStrike Falcon Integration](https://kravensecurity.com/python-threat-hunting-tools-part-12-misp-and-crowdstrike-falcon-integration/): Make your threat hunting process more efficient by integrating MISP and CrowdStrike Falcon EDR so you can automate uploading your IOCs for detection. - [Threat Intelligence with MISP Part 7 - Exporting IOCs](https://kravensecurity.com/threat-intelligence-with-misp-part-7-exporting-iocs/): Discover how to turn MISP attributes into Indicators of Compromise that you can export as a CSV file and upload to your security solution for detection. - [Python Threat Hunting Tools: Part 11 - A Jupyter Notebook for MISP](https://kravensecurity.com/python-threat-hunting-tools-jupyter-notebook-for-misp/): Learn how to create a Jupyter Notebook that you can use to query your MISP instance. This will drastically speed up your threat intelligence operations! - [Threat Intelligence with MISP Part 6 - Using the API](https://kravensecurity.com/threat-intelligence-with-misp-part-6-using-the-api/): Learn to use the MISP API to make the most of your MISP instance. You will see how to get statistics about your MISP instance, search for attributes and events, and visualize data you've added to your instance. - [How to Build a Free CTI Aggregator: The Full Guide 2026](https://kravensecurity.com/creating-your-own-cti-aggregator-for-free/): Learn how to build a CTI aggregator to efficiently gather and organize open source cyber threat intelligence from a range of threat feeds in one platform. - [Threat Intelligence with MISP: Part 5 - Searching and Filtering](https://kravensecurity.com/threat-intelligence-with-misp-part-5-searching-and-filtering/): Learn how to search and filter MISP events and attributes to find threat intelligence relevant to you. - [Threat Intelligence with MISP: Part 4 - Using Feeds](https://kravensecurity.com/threat-intelligence-with-misp-part-4-using-feeds/): Learn how to add open-source threat intelligence feeds to your MISP instance so you can begin rapidly populating the threat intelligence platform with the latest data. - [Threat Intelligence with MISP: Part 3 - Creating Events](https://kravensecurity.com/threat-intelligence-with-misp-part-3-creating-events/): Learn how to start using MISP. You will learn about MISP events, how to create them, and how to add context to them using MISP's galaxies and taxonomies - [Visual Threat Intelligence: A Masterpiece of Infographics and Storytelling ](https://kravensecurity.com/complete-book-review-of-visual-threat-intelligence/): Let’s take a look at Visual Threat Intelligence by Thomas Roccia and discover why it is so popular in the cyber security community in this complete review. - [Threat Intelligence with MISP: Part 2 - MISP Installation](https://kravensecurity.com/threat-intelligence-with-misp-part-2-setting-up-misp/): This MISP installation guide covers how to install MISP using the MISP Docker image. A must-read MISP tutorial to get started using MISP today! - [Cyber Threat Intelligence with MISP: Part 1 - What is MISP?](https://kravensecurity.com/cyber-threat-intelligence-with-misp-part-1-what-is-misp/): Discover the premier open-source threat intelligence sharing platform, its key features, and how you can use it to elevate your security posture! - [5 Mistakes I Made as a New Cyber Threat Intelligence Analyst](https://kravensecurity.com/the-5-mistakes-new-cyber-threat-intelligence-analysts-make/): Being a cyber threat intelligence analyst is a difficult job. Here are the top 5 mistakes I made when I first started that you can learn from and avoid. - [Threat Profiling: How to Understand Hackers and Their TTPs](https://kravensecurity.com/threat-profiling-how-to-understand-hackers-and-their-ttps/): Begin understanding how attackers think by performing threat profiling to map out how they might attack your organization using the MITRE ATT&CK matrix. - [How Cyber Security Work Is Changing? The New Gig Economy](https://kravensecurity.com/how-cyber-security-work-is-changing-with-the-gig-economy/): Discover how the cyber world is shifting to a new era of employment with the emergence of the gig economy so you can take advantage of it and stay relevant. - [How to Build an Incident Response Playbook: Full Guide 2026](https://kravensecurity.com/how-to-build-enterprise-ready-incident-response-playbooks/): Discover how to build an incident response playbook in this complete guide. Empower your security team to respond to cyber security incidents efficiently. - [Day in the Life of a Senior Threat Intelligence Analyst](https://kravensecurity.com/a-day-in-the-life-of-a-senior-threat-intelligence-analyst/): Peek into a senior threat intelligence analyst's day. Discover the daily tasks, from threat hunting and vulnerability analysis to program development. - [5 Ways to Use ChatGPT to Create Cyber Security Tools](https://kravensecurity.com/learn-5-ways-to-use-chatgpt-to-create-cyber-security-tools/): Learn 5 ways to use AI and ChatGPT to create custom tools that you can use in your day-to-day work to improve your organization’s cyber security posture. - [Python Threat Hunting Tools: Part 10  — The Power of Jupyter Notebooks](https://kravensecurity.com/python-threat-hunting-tools-jupyter-notebooks/): Discover what Jupyter Notebooks are and learn how to create your own to structure your threat hunting workflow and improve your efficiency. - [7 Best Notetaking Apps for Cyber Security Professionals 2026](https://kravensecurity.com/learn-7-of-the-best-cyber-security-notetaking-apps/): Discover the 7 best notetaking apps for cyber security. Capture your thoughts, document tasks that need to be done, and establish a knowledge base. - [Python Threat Hunting Tools: Part 9 — Creating Python Packages with Poetry](https://kravensecurity.com/python-threat-hunting-tools-creating-packages/): Learn to create your own Python packages using the Python module Poetry. This lets you easily share your threat hunting tools with the community. - [Why Soft Skills Matter in Cyber Security and Practicing Them](https://kravensecurity.com/why-soft-skills-matter-in-cyber-security/): Discover what soft skills are and why they are so important to master if you want to excel in the cyber security industry and reach your full potential. - [Why Fake It Till You Make Is a Lie: Fight Imposter Syndrome](https://kravensecurity.com/why-fake-it-till-you-make-it-is-a-lie-and-how-to-fight-imposter-syndrome/): Find out how you can fight imposter syndrome by finding confidence in the work you do rather than living a lie and faking it till you make it. - [Python Threat Hunting Tools: Part 8 — Parsing JSON](https://kravensecurity.com/python-threat-hunting-tools-parsing-json/): Discover how to extract valuable information from JSON to analyze it and turn it into threat intelligence or IOCs to hunt for in your environment. - [Python Threat Hunting Tools Part 7 — Parsing CSV](https://kravensecurity.com/python-threat-hunting-tools-parsing-csv/): Discover how to extract data from a CSV file to analyze it and turn it into threat intelligence or IOCs to hunt for in your environment. - [3 Things KFC and Good Threat Intelligence Have in Common](https://kravensecurity.com/the-3-things-kfc-and-good-threat-intelligence-have-in-common/): Ever wondered what KFC and threat intelligence have in common? Discover how relevance, timeliness, and actionability relate good threat intelligence. - [Python Threat Hunting Tools Part 6 — Creating EXEs from Python Files](https://kravensecurity.com/python-threat-hunting-tools-creating-executables/): Discover how to create standalone executable programs from your Python scripts that you can use on any Windows operating system using the Python module py2exe. - [Python Threat Hunting Tools: Part 5 — Command Line Arguments](https://kravensecurity.com/python-threat-hunting-tools-part-5-command-line-arguments/): Learn how to give your threat hunting tools command line arguments that modify their behavior when they are executed. - [Want to be a Cyber Security Unicorn? Master Diverse Skills](https://kravensecurity.com/how-to-become-a-cyber-security-unicorn-with-diverse-skills/): Find out how to be a stand out in the cyber security industry and reach the legendary status of a cyber security unicorn by mastering diverse skills. - [Python Threat Hunting Tools: Part 4 — Browser Automation](https://kravensecurity.com/python-threat-hunting-tools-browser-automation/): Learn to use browser automation to automate the threat intelligence process when API access is not available or behind a paywall. - [Learn 10 ways to use ChatGPT for Threat Hunting Right Now!](https://kravensecurity.com/learn-10-ways-to-use-chatgpt-for-threat-hunting/): Discover 10 practical ways you can take advantage of the AI takeover and use ChatGPT to help you perform threat hunting and enhance your capabilities. - [Python Threat Hunting Tools: Part 3 — Interacting with APIs](https://kravensecurity.com/python-threat-hunting-tools-interacting-with-apis/): Welcome back to this series on building threat hunting tools! Today how interacting with APIs can help us threat hunt. - [5 Reasons Why a Threat Intelligence Platform Will Improve Your Business](https://kravensecurity.com/learn-5-reasons-a-threat-intelligence-platform-will-improve-your-business/): Find out 5 reasons why a threat intelligence platform will improve your business and help your security operations tackle the latest emerging threats. - [Python Threat Hunting Tools: Part 2 — Web Scraping](https://kravensecurity.com/python-threat-hunting-tools-web-scraping/): Learn about web scraping and to create your own tool to scrape threat intelligence from CISA's weekly vulnerability summary. - [Threat Intelligence vs Threat Hunting: What is the Perfect Pipeline?](https://kravensecurity.com/threat-intelligence-vs-threat-hunting-what-is-the-perfect-pipeline/): Discover how to integrate your cyber threat intelligence with your threat hunting tasks to create the perfect pipeline and streamline your operations. - [Python Threat Hunting Tools: Part 1 — Why?](https://kravensecurity.com/python-threat-hunting-tools-why/): Learn how to build your own threat hunting tools with Python in this new series! First, let’s find out why it is important to build your own tools. - [Free vs Paid Cyber Security Training: The Secret to Career Success](https://kravensecurity.com/free-vs-paid-cybersecurity-training/): Training is vital for success in cybersecurity. Let's explore the options you have at your disposal and perhaps the best path to follow to achieve your goals. - [Hunting for Persistence with Cympire: Part IV — Startup Folder](https://kravensecurity.com/hunting-for-startup-folder-persitence-with-cympire/): Learn how attackers use the Windows Startup Folder to maintain persistence once they’ve compromised a machine. Then hunt for these malicious Startup Folder items. - [How to Arm Yourself with Custom Sigma Rules](https://kravensecurity.com/lock-load-arming-yourself-with-custom-sigma-rules/): Discover how to create your own custom Sigma rules to hunt for the latest threats that are affecting your environment and thwart threat actors. - [Hunting for Persistence with Cympire: Part III — Services](https://kravensecurity.com/hunting-for-persistent-services-with-cympire/): Learn how attackers use Windows services to maintain persistence once they’ve compromised a machine. Then see how to hunt for these malicious services. - [How to Arm Yourself with Threat Intelligence](https://kravensecurity.com/lock-load-arming-yourself-with-threat-intelligence/): Learn how to use threat intelligence articles, the MITRE ATT&CK framework, and Sigma rules to perform threat-informed hunting using Splunk queries. - [Hunting for Persistence with Cympire: Part II — Scheduled Tasks](https://kravensecurity.com/hunting-for-scheduled-tasks-with-cympire/): Learn how attackers use scheduled tasks to maintain persistence once they’ve compromised a machine. Then see how to hunt for these tasks. - [MITRE ATT&CK Framework: Holy Bible of Threat Intelligence](https://kravensecurity.com/mitre-attack-framework/): Let's explore the MITRE ATT&CK framework and find out why it's a must know tool for any cyber threat intelligence analyst looking to tackle the latest threats. - [Hunting for Persistence with Cympire: Part I — Registry Run Keys](https://kravensecurity.com/hunting-for-registry-run-keys-with-cympire/): Learn how attackers use Windows registry keys to maintain persistence once they’ve compromised a machine. Then see how to hunt for these malicious keys. - [Elevate Your Threat Detections Using the Almighty Pyramid of Pain](https://kravensecurity.com/the-almighty-pyramid-of-pain/): Discover how to turn a bad guy's day into a nightmare using the Pyramid of Pain to elevate your threat detections and increase the cost on adversaries. - [Let Us Find Out Whodunit](https://kravensecurity.com/let-us-find-out-whodunit/): Whodunit is a tool that can be used to identify the most likely Advanced Persistent Threat group responsible for an attack. Let's find out how to use it! - [Threat Hunting With Velociraptor III - Hunting Demo](https://kravensecurity.com/threat-hunting-with-velociraptor-hunting-demo/): Learn how to use Velociraptor’s threat hunting capabilities to identify malicious activity associated with real-world malware and threat actors in this demo. - [Threat Hunting With Velociraptor II: Environment Setup](https://kravensecurity.com/threat-hunting-with-velociraptor-environment-setup/): Discover how to create a virtualized threat hunting environment and use Velociraptor as a threat hunting tool to sniff out malicious reverse shells. - [Threat Hunting With Velociraptor I - Introduction](https://kravensecurity.com/threat-hunting-with-velociraptor-introduction/): Learn what threats are, what threat hunting is, and the basic security requirements needed to start a threat hunting program in this series introduction. - [Creating a Virtualized Malware Analysis Lab Environment](https://kravensecurity.com/malware-analysis-lab-environment/): Learn how to create a safe and secure malware analysis environment that is tailored towards your analysis needs using the power of virtualization. - [How to Create a Home Lab: Virtualize all the Things!](https://kravensecurity.com/virtualise-all-the-things/): Discover the power of virtualization and how to create your own home lab environment for malware analysis, threat hunting, and software development. - [CyberChef the Basics: A Quick Guide to The Most Versatile Cyber Tool](https://kravensecurity.com/cyberchef-guide/): Discover powerful CyberChef magic in this CyberChef tutorial. Learn how to streamline data analysis and master the power of this cyber security tool. - [Triaging the Week 074 ](https://kravensecurity.com/triaging-the-week-074/): ClickFix Attacks Target macOS and Booking.com Users, Supply Chain Attack Target Gluestack npm packages, and AI Vulnerability in Microsoft 365 Copilot in triaging the week 074. - [Triaging the Week 073](https://kravensecurity.com/triaging-the-week-073/): Web browsers targeted with weak extensions and ClickFix attacks, DocuSign phishing emails, and Microsoft and CrowdStrike collaboration on threat actor naming in triaging the week 073. - [Triaging the Week 072](https://kravensecurity.com/triaging-the-week-072/): Passwordless authentication is the future, DragonForce ransomware targets UK retailers, and Linux wiper hits the scene in triaging the week 072. - [Threat Profiling 101: How to Create a Threat Profile (2026)](https://kravensecurity.com/threat-profiling/): Discover how to develop effective threat profiles that identify and prioritize relevant cyber threats for your organization and provide threat-informed defence. - [Triaging the Week 071 ](https://kravensecurity.com/triaging-the-week-071/): Critical vulnerabilities in SAP NetWeaver and Apple AirBorne, New InfoStealers, and ransomware gangs change branding model in triaging the week. - [How to Build a Cyber Threat Intelligence Collection Plan in 2026](https://kravensecurity.com/intelligence-collection-plan/): Discover how you can build a cyber threat intelligence collection plan to make your intelligence actionable by mapping each to data sources and daily tasks. - [Triaging the Week 070](https://kravensecurity.com/triaging-the-week-070/): ClickFix attacks dominate headlines, MITRE ATT&CK v17 released, and major UK store hit by cyber attack in triaging the week 070. - [How to Prioritize Customer Needs: Priority Intelligence Requirements](https://kravensecurity.com/priority-intelligence-requirements/): Learn how to create priority intelligence requirements (PIRs) that ensure your cyber threat intelligence team focuses on what matters most to your business. - [Triaging the Week 069 ](https://kravensecurity.com/triaging-the-week-069/): CVE program in chaos, vulnerabilities hit Fortinet devices and Windows Task Scheduler, and coding scams trick developers in triaging the week 069. - [IPCE + PESTLE Analysis: Intelligence Preparation of the Cyber Environment](https://kravensecurity.com/ipce-and-pestle-analysis/): Learn how to use Intelligence Preparation of the Cyber Environment (IPCE) and PESTLE analysis to evaluate risks in your business’s cyber environment. - [Triaging the Week 068](https://kravensecurity.com/triaging-the-week-068/): Malicious Python packages and VSCode extensions, flaws in Fortinet and CrushFTP, and EC2 sites impacted by SSRF bugs in triaging the week 068. - [The 8 Principles of Intelligence: Foundations for Good CTI](https://kravensecurity.com/principles-of-intelligence/): Unlock the eight key principles of intelligence to ensure your next CTI product is actionable, timely, and tailored to your intelligence consumer. - [Triaging the Week 067](https://kravensecurity.com/triaging-the-week-067/): North Korea expands fake IT workers scheme, QR code phishing is the hot new attack vector, and critical RCE is Apache Parquet drops in triaging the week 067. - [How to Plan a CTI Project: Key Documentation You Need](https://kravensecurity.com/cti-project-planning/): Learn how to plan a CTI project and the key documentation you need in this comprehensive guide. Avoid roadblocks and set your project up for success. - [Threat Actors: How to Unmask and Understand Hackers](https://kravensecurity.com/threat-actors/): Discover how to identify threat actors, their motivation, intent, and capability so you can prioritize defenses and allocate resources effectively. - [Triaging the Week 066](https://kravensecurity.com/triaging-the-week-066/): Identity attack and InfoStealer surge in 2025, Apache Tomcat vulnerability and GitHub supply chain attack impact many, and Windows zero-day fuels APT attacks in triaging the week 066. - [Triaging the Week 065](https://kravensecurity.com/triaging-the-week-065/): X hit by DDoS attack, 300+ critical infrastructure orgs targeted by Medusa ransomware, and AI-powered fake GitHub repos spread malware in triaging the week 065. - [Top 5 Challenges of Building a CTI Team (+ How to Overcome)](https://kravensecurity.com/top-5-challenges-of-building-a-cti-team/): Discover the top 5 challenges of building a CTI team and how you can overcome them, from talent acquisition to operational integration, in this guide. - [Triaging the Week 064](https://kravensecurity.com/triaging-the-week-064/): New ClickFix attacks use Microsoft SharePoint, fake ransomware notes, and AI-generated CEO used in phishing scam in triaging the week 064. - [Triaging the Week 063](https://kravensecurity.com/triaging-the-week-063/): Apple removed E2EE in the UK, a record-breaking crypto heist, and PayPal phishing emails run rampant in triaging the week 063. - [The History of Cyber Threat Intelligence: Quick Fire Guide (2026)](https://kravensecurity.com/history-of-cyber-threat-intelligence/): Discover the history of cyber threat intelligence, from the origins of intelligence to modern CTI, in this ultimate guide on the history of cyber threats. - [Triaging the Week 062](https://kravensecurity.com/triaging-the-week-062/): Android fights back against scammer, massive data breaches, and Signal targeted in phishing campaigns in triaging the week 062. - [Triaging the Week 061](https://kravensecurity.com/triaging-the-week-061/): Major crackdown on 8Base ransomware site and LockBit hackers, ClickFix attacks on the rise, and Ivanti patches more critical vulnerabilities in triaging the week 061. - [The CTI Team Explained: Roles and Responsibilities You Need](https://kravensecurity.com/cti-team/): What does a successful CTI team look like? Discover the key roles and responsibilities required to build a successful threat intelligence team in this guide. - [Triaging the Week 060 ](https://kravensecurity.com/triaging-the-week-060/): DeepSeek AI tools impersonated, Five Eyes release tell us how to secure network devices, and zero-click WhatsApp vulnerability spotted in-the-wild in triaging the week 060. - [Triaging the Week 059](https://kravensecurity.com/triaging-the-week-059/): Vulnerabilities in Git and Node JS, hackers abuse SSH tunnels and SimpleHelp RMM, and DeepSeek AI hit by cyber attack in traiging the week 059 - [STIX/TAXII: A Complete Guide to Automated Threat Intelligence Sharing](https://kravensecurity.com/stix-and-taxii-a-full-guide/): Harness the power of automation for cyber threat intelligence in this guide on STIX/TAXII. Learn STIX objects and the TAXII protocol for analysis and sharing. - [Triaging the Week 058](https://kravensecurity.com/triaging-the-week-058/): Malicious Python packages and fake websites, vulnerabilities in tunneling protocols, and Trump pardons Silk Road creator in triaging the week 058. - [New Free Training Courses and Threat Hunting Packages!](https://kravensecurity.com/free-training-courses-and-threat-hunting-packages/): Two new initiatives released at Kraven Security! New free training courses drop and daily threat hunting packages based on OSINT reports. - [Triaging the Week 057](https://kravensecurity.com/triaging-the-week-057/): Vulnerabilities for MacOS and Google OAuth, cybercriminals use AI and AWS features for ransomware, and high-speed Microsoft 365 Password Attacks in traiging the week 057. - [Triaging the Week 056](https://kravensecurity.com/triaging-the-week-056/): AI spearphising, new malware targeting Android, and Ivanti zero-day flaw in triaging the week 056. - [Triaging the Week 055](https://kravensecurity.com/triaging-the-week-055/): Clop ransomware gang behind massive Cleo breach, malicious ads and AI-driven scam plague the Internet, and Microsoft Teams and AnyDesk used to deliver malware in triaging the week 055. - [Web Scraping Threat Intelligence Using Octoparse: Full Guide (2026)](https://kravensecurity.com/web-scraping-using-octoparse/): Learn how to create your own custom web scraping tool to gather cyber threat intelligence using the the powerful, no-code platform Octoparse. - [Triaging the Week 054](https://kravensecurity.com/triaging-the-week-054/): Fake apps target mobile devices, QR codes bypass browser sandboxing, and Visual Studio Code dev tunnels exploited in triaging the week 054. - [Triaging the Week 053](https://kravensecurity.com/triaging-the-week-053/): Notorious ransomware affiliate arrested, new phishing attack spotted, and Cloudflare developer domains abused by hackers in triaging the week 053. - [Triaging the Week 052](https://kravensecurity.com/triaging-the-week-052/): Cyber security contractor runs wild, NHS hit by another cyber attack, and the first UEFI bootkit for Linux revealed in triaging the week 052. - [C2 Hunting 101: How to Find C2 Servers with Shodan](https://kravensecurity.com/c2-hunting-using-shodan/): Discover the power of C2 hunting and learn to hunt for C2 servers so you can stay ahead of the hackers. This guide teaches you C2 hunting using Shodan. - [Triaging the Week 051](https://kravensecurity.com/triaging-the-week-051/): SVG attachments used for phishing, critical vulnerabilities in Apple and Ubuntu Linux, and Phobos ransomware admin gets charged in triaging the week 051. - [Triaging the Week 050 ](https://kravensecurity.com/triaging-the-week-050/): Scam texts target the vulnerable, massive data breaches, and new macOS malware using Flutter in triaging the week 050. - [The Attack Navigator: A Powerful Tool for Visualizing Cyber Attacks ](https://kravensecurity.com/attack-navigator/): Unlock the power of the ATT&CK Navigator, discover its many use cases, and learn to visualize and map attack techniques through a user-friendly interface. - [Triaging the Week 049](https://kravensecurity.com/triaging-the-week-049/): Google uses AI to find vulnerabilities, SharePoint RCE vulnerability exploited, and Canada shuts down TikTok in triaging the week 049. - [ATT&CK Powered Suit: Streamline Your Research and Save Time ](https://kravensecurity.com/attck-powered-suit/): The ATT&CK Powered Suit puts the entire ATT&CK knowledge base at your fingertips. Streamline your research and save valuable time with this new tool from MITRE. - [Triaging the Week 048](https://kravensecurity.com/triaging-the-week-048/): Microsoft Teams and fake CAPTCHAs used in cyber attacks, RDP used for phishing, and vulnerabilities discovered in open-source AI tools in triaging the week 048. - [Triaging the Week 047](https://kravensecurity.com/triaging-the-week-047/): Malware hiding in image files, new AI attacks, and LinkedIn becomes magnet for cyber scams in triaging the week 047. - [Collection Management Framework Template (+FREE Download)](https://kravensecurity.com/collection-management-framework-template/): This collection management framework template provides you with the structure to effectively document your data sources and understand how to use them. - [Triaging the Week 046](https://kravensecurity.com/triaging-the-week-046/): New phishing tactics, escalating cyber threats, and PIN-stealing fake lock screens in triaging the week 046. - [Triaging the Week 045](https://kravensecurity.com/triaging-the-week-045/): Cybercriminals look for Telegram alternatives, APTs target telecoms and air-gapped systems, and API and bot attacks cost businesses billions in triaging the week 045. - [Triaging the Week 044](https://kravensecurity.com/triaging-the-week-044/): Vulnerabilities in gas tanks, AI-powered crypto stealers, and deep fake phishing sites spread malware in triaging the week 044. - [Triaging the Week 043](https://kravensecurity.com/triaging-the-week-043/): Hackers use AI to write malware, Telegram starts cooperating with law enforcement, and Europol dismantles global phishing operation in triaging the week 043. - [Triaging the Week 042](https://kravensecurity.com/triaging-the-week-042/): New malware triggers kiosk mode, ransomware gangs abuse cloud tools, and pagers start exploding in Lebanon in triaging the week 042. - [Triaging the Week 041](https://kravensecurity.com/triaging-the-week-041/): New Android malware uses OCR, Chinese APT weaponizes VSCode, and RAMBO attack steals data from air-gapped system’s RAM in triaging the week 041. - [Triaging the Week 040](https://kravensecurity.com/triaging-the-week-040/): GitHub comments spread malware, Google Sheets used as C2, and YubiKeys come under attack in triaging the week 040. - [Intelligence Requirements Template 2026 (PDF + Word Doc Download)](https://kravensecurity.com/intelligence-requirements-template/): This free intelligence requirements template allows you to document your intelligence requirements and kickstart your cyber threat intelligence program. - [Triaging the Week 039](https://kravensecurity.com/triaging-the-week-039/): New stealthy malware, Telegram founder arrested in France, and massive QR code phishing in triaging the week 039. - [Cyber Threat Intelligence Report Template (+FREE Download) ](https://kravensecurity.com/cyber-threat-intelligence-report-template/): A cyber threat intelligence report template saves you and your CTI team valuable time and effort. Here is a FREE report template you can use today! - [Triaging the Week 038](https://kravensecurity.com/triaging-the-week-038/): New macOS threat, new ransomware gang, and new hacking tool leverages the cloud in triaging the week 038. - [Triaging the Week 037](https://kravensecurity.com/triaging-the-week-037/): Hackers target macOS, flaws in GitHub Actions and Azure AI health bot, and the latest insights from the attack surface landscape in triaging the week 037. - [Triaging the Week 036](https://kravensecurity.com/triaging-the-week-036/): Home users targeted by ransomware, student devices hacked, and IT staff come under attack by new malware in triaging the week 036. - [Triaging the Week 035](https://kravensecurity.com/triaging-the-week-035/): Cybercrime insights, big ransomware payouts, and mass SMS infostealer campaign in triaging the week 035. - [Triaging the Week 034](https://kravensecurity.com/triaging-the-week-034/): NCA has a major takedown, critical Telegram vulnerability, and threat actors exploit the CrowdStrike fiasco in triaging the week 034. - [Triaging the Week 033](https://kravensecurity.com/triaging-the-week-033/): Malicious versions of jQuery, Russian bots taken down, and ViperSoftX malware gets an upgrade in triaging the week 033. - [Triaging the Week 032](https://kravensecurity.com/triaging-the-week-032/): Critical OpenSSH Flaw, Google Offers Big Bucks for KVM Zero-Days, and Child Predators Unmasked Using Infostealer Malware in triaging the week 032. - [Triaging the Week 031](https://kravensecurity.com/triaging-the-week-031/): Rise in Android malware, new GrimResource Windows attack, and WikiLeaks founder Julian Assange released in triaging the week 031. - [Essential Threat Intelligence Sources You Need to Know](https://kravensecurity.com/threat-intelligence-sources/): Intelligence collection sources are the most important component of a CTI program. This guide will teach you what they are and how to use them. - [Triaging the Week 030](https://kravensecurity.com/triaging-the-week-030/): Users get targeted with fake errors and new phishing kits, Scattered Spider hacker gets arrested, and the Kraken crypto exchanges loses millions in triaging the week 030. - [CTI Analysis Bias: How to Overcome Your Prejudices During Analysis](https://kravensecurity.com/cti-analysis-bias/): CTI analysis bias is inherent in all analysts. You must learn how to overcome it to produce accurate intelligence assessments. This guide will teach you how. - [Triaging the Week 029](https://kravensecurity.com/triaging-the-week-029/): New phishing techniques and campaigns are revealed, leaky GitHub token leads to NYT breach, and Microsoft Azure tags come under attack in triaging the week 029. - [CTI Report Writing 101: How to Effectively Communicate Threat Intelligence](https://kravensecurity.com/cti-report-writing/): CTI report writing is an essential threat intelligence skill. This guide will teach how to write a threat intelligence report with CTI report examples. - [Triaging the Week 028](https://kravensecurity.com/triaging-the-week-028/): Snowflake breach impacts major orgs, TitTok hit by zero-day, and several London hospitals caught up in ransomware attack in triaging the week 028. - [Estimative Language: How to Add Confidence and Probability in Assessments](https://kravensecurity.com/estimative-language/): Learn how to add confidence and probability to your cyber threat intelligence reports for better decisions in this comprehensive guide on estimative language. - [Triaging the Week 027](https://kravensecurity.com/triaging-the-week-027/): Check Point VPN attacked, Hackers abuse Cloudflare Workers and Stack Overflow, and a new ransomware group linked to North Korea in triaging the week 027. - [Intrusion Analysis 101: How to Fully Investigate Malicious Cyber Intrusions](https://kravensecurity.com/intrusion-analysis/): Learn how to perform intrusion analysis in this comprehensive guide to investigating and responding to security incidents. Includes practical examples. - [Triaging the Week 026](https://kravensecurity.com/triaging-the-week-026/): Dark web marketplace gets taken down, new attacks abuse the cloud and legitimate services, and China uses ORB networks to evade detection in triaging the week 026. - [Crown Jewel Analysis: How to Protect What Matters Most](https://kravensecurity.com/crown-jewel-analysis/): Learn how to protect what matters most to your business using the crown jewel analysis. This guide will teach you about this fundamental risk management tool. - [Triaging the Week 025](https://kravensecurity.com/triaging-the-week-025/): New hacking attacks target cloud and DNS, MITRE releases a new framework, and Windows Quick Access gets abused in triaging the week 025. - [Traffic Light Protocol: How to Classify Threat Intelligence using TLP](https://kravensecurity.com/traffic-light-protocol/): Discover the Traffic Light Protocol (TLP) in this full guide. Learn how to use it for classifying threat intelligence to ensure secure intelligence sharing. - [Triaging the Week 024](https://kravensecurity.com/triaging-the-week-024/): New MacOS malware and DHCP attacks, LockBit admin locked up, and hackers pose as journalists in triaging the week 024. - [5 Cyber Kill Chain Challenges and How to Overcome Them!](https://kravensecurity.com/top-5-cyber-kill-chain-challenges/): What are the top 5 cyber kill chain challenges you will face, and how can you overcome them? Read this guide to find out! - [Triaging the Week 023](https://kravensecurity.com/triaging-the-week-023/): Okta comes under attack, dating scams are on the rise, and millions of Docker repositories are pushing malware in triaging the week 023 - [YARA Rules: How to Detect Malware with Custom Rules](https://kravensecurity.com/yara-rules/): Learn how to use YARA rules to create your own custom detection rules. Discover how they can protect you from malware and how to use them in the real world. - [Triaging the Week 022](https://kravensecurity.com/triaging-the-week-022/): Learn to create honey files, discover why programming is needed for cyber security, and raise your productivity in triaging the week 022. - [Analysis of Competing Hypotheses: The Ultimate Technique for Finding Answers](https://kravensecurity.com/analysis-of-competing-hypotheses/): Discover the power of the structured analytic technique "Analysis of Competing Hypotheses" in this guide. Learn how to efficiently analyze competing hypotheses. - [Triaging the Week 021](https://kravensecurity.com/triaging-the-week-021/): Zero-day in Palo Alto firewalls, new steganography phishing emails, and Chirp Systems’ smart locks failing in triaging the week 021. - [The Diamond Model of Intrusion Analysis: Simple Intelligence-Driven Analysis](https://kravensecurity.com/diamond-model-analysis/): Discover the Diamond Model of intrusion analysis and elevate your cyber threat intelligence skills in this comprehensive guide on the Diamond Model. - [Triaging the Week 020](https://kravensecurity.com/triaging-the-week-020/): Scams everywhere, Israeli spy chief sucks at opsec, and a new flaw in SharePoint lets hackers evade detection in triaging the week 020. - [Top 5 Challenges With Indicators and How to Overcome Them](https://kravensecurity.com/top-5-challenges-with-indicators/): Discover the top five challenges with indicators (IOCs) and how to overcome them to improve the effectiveness of your cyber security operations. - [Triaging the Week 019](https://kravensecurity.com/triaging-the-week-019/): Backdoor found in open-source tool, India rescues citizens from cyber slavery, and Microsoft slammed over breach in triaging the week 019. - [How to Create Your Own Malware Analysis Environment](https://kravensecurity.com/automated-malware-analysis-environment/): Learn how to create your own malware analysis environment and automate its deployments in minutes using the power of infrastructure as code in this guide. - [Triaging the Week 018](https://kravensecurity.com/triaging-the-week-018/): Phishing-as-a-service on the rise, US says SQL injection vulnerabilities are unforgivable, and free VPN apps enable cybercrime in triaging the week 018. - [Threat Modeling: A Staple of Great Cyber Threat Intelligence](https://kravensecurity.com/what-is-threat-modeling/): Learn what threat modeling is, why it is important, and how to create a threat model using industry-leading methodologies in this comprehensive guide. - [Triaging the Week 017](https://kravensecurity.com/triaging-the-week-017/): Hackers focus on attacks through the web, CISA shares tips for defending critical infrastructure, and GitHub releases new feature in triaging the week 017. - [Collection Management Framework: How to Manage Your Data Sources](https://kravensecurity.com/collection-management-framework/): Learn how to effectively manage all your cyber threat intelligence data sources using a collection management framework. Increase CTI efficiency today! - [Triaging the Week 016](https://kravensecurity.com/triaging-the-week-016/): Microsoft SCCM vulnerable to attack, Tor releases new features, and Google Gemini AI comes under scrutiny in triaging the week 016. - [The Cyber Kill Chain: A Powerful Model for Analyzing Cyberattacks](https://kravensecurity.com/cyber-kill-chain/): Learn how to use the cyber kill chain to understand cyber attacks, analyze intrusions, and plan your cyber defenses in this comprehensive guide. - [Triaging the Week 015](https://kravensecurity.com/triaging-the-week-015/): Phobos ransomware strikes critical infrastructure, the NSA teaches how to reach zero-trust, and hackers abuse QEMU in triaging the week 015 - [Top 5 Challenges When Creating Intelligence Requirements](https://kravensecurity.com/challenges-when-creating-intelligence-requirements/): Learn about the top 5 challenges when creating intelligence requirements and strategies you can use to overcome them in this guide. - [Triaging the Week 014](https://kravensecurity.com/triaging-the-week-014/): New threat intelligence reports released, Russia moves to hacking the cloud, and NIST updates its cyber security framework in triaging the week 014. - [How to Setup Your Own Local Kubernetes Cluster: Local K8s with Terraform and Ansible](https://kravensecurity.com/creating-local-kubernetes-cluster/): Learn how to create and build your own Kubernetes cluster using Terraform, Ansible, and the power of infrastructure as code (IaC). Run K8s Locally Today! - [Triaging the Week 013](https://kravensecurity.com/triaging-the-week-013/): Google open source AI tool, crackdown on LockBit ransomware, and new attacks that manipulate virtual assistants in triaging the week 013. - [Detection as Code: A Pipeline That Won't Flood Your SOC](https://kravensecurity.com/detection-as-code/): Learn detection as code with a four-stage pipeline to validate, translate, test, and deploy Sigma rules, plus the mistakes that sink SOC migrations. - [Triaging the Week 135](https://kravensecurity.com/triaging-the-week-135/): Agentic AI Crosses the Line // Social Engineering at Industrial Scale // The Browser Is the Endpoint Now // Identity and Cloud // Adversary Infrastructure in triaging the week 135. - [Triaging the Week 134](https://kravensecurity.com/triaging-the-week-134/): The Collapsing Exploit Window // AI Systems as the New Attack Surface // Identity Is the Perimeter // Hiding in Plain Sight // Scams at Scale in triaging the week 134. - [Lazarus Group: The Complete Guide to North Korea's Billion-Dollar Hacking Machine](https://kravensecurity.com/lazarus-group-threat-profile/): Discover how the Lazarus Group became the world's most successful cybercrime syndicate, and the detection gaps most security teams still miss. - [Triaging the Week 133](https://kravensecurity.com/triaging-the-week-133/): Trusted Software Is the Delivery Vehicle // The Supply Chain Turns Hostile // Your AI Toolchain Under Attack // Adversaries Are Operationalizing AI // Already Inside the Walls in triaging the week 133. - [Triaging the Week 132](https://kravensecurity.com/triaging-the-week-132/): ClickFix Goes Industrial // Identity Is the Only Perimeter // AI as Target and Threat Actor // Nation-State Ops Move From Espionage to Physical Impact // Law Enforcement Crackdowns in triaging the week 132. - [Sigma Rules Explained: Architecture, pySigma, Modifiers, & Correlation](https://kravensecurity.com/sigma-rules-explained/): Learn how Sigma rules, modifiers, and pySigma power platform-agnostic detection engineering and threat hunting, plus the pitfalls tutorials skip. - [Triaging the Week 131](https://kravensecurity.com/triaging-the-week-131/): ClickFix & macOS Endpoint Under Siege // Blinding the Defender // Developer Pipeline & AI Assistants Targeted // The Extortion Economy & Its Infrastructure // Fraud at Scale in triaging the week 131. - [Triaging the Week 130](https://kravensecurity.com/triaging-the-week-130/): AI as Weapon and Target // Your Marketplace Is Your Perimeter // Ransomware & the Vanishing Patch Window // The Hiring Pipeline Is an Attack Vector // SaaS, Silicon, and Statecraft in triaging the week 130. - [How to Detect North Korean Remote Workers Hiding Inside Your Company](https://kravensecurity.com/north-korean-remote-workers/): North Korean remote workers pass interviews, then extort you. Learn the DPRK remote IT worker hiring pipeline, TTPs, and seven detection opportunities. - [Triaging the Week 129](https://kravensecurity.com/triaging-the-week-129/): The Package Registry Is the Attack Surface // ClickFix Has Gone Cross-Platform // Trust Guarantees That Didn't Hold // The Perimeter You Stopped Looking At // Agentic AI for Offense and Defense in triaging the week 129 - [CTI For SMB: When Your Small Business Is Actually Ready For Threat Intelligence](https://kravensecurity.com/cti-for-smb-when-to-get-started/): Learn when your business is ready for CTI for SMB, which controls come first, and a 60-day roadmap to run threat intelligence on a real budget. - [Triaging the Week 128](https://kravensecurity.com/triaging-the-week-128/): Your AI Agent Is the New Insider Threat // AI Infrastructure Is Now a Primary Target // Developers Are the Softest Path Into the Supply Chain // Identity & Trusted Platforms as the Attack Surface // Patch, Then Assume Breach in triaging the week 128. - [Triaging the Week 127](https://kravensecurity.com/triaging-the-week-127/): The Agentic Attack Surface // The MFA Bypass Era // Poisoned Supply Chains & Fake Repos // Stealers, Ransomware & the macOS Frontier // Infrastructure, Privacy & Critical Patches in triaging the week 127. - [Triaging the Week 126](https://kravensecurity.com/triaging-the-week-126/): Identity Under Siege — Device Code Phishing, Vishing & MFA Bypass // AI Coding Agents Under Attack // Supply Chain & Dev Ecosystem Residential Proxies, Botnets, & ORBs in triaging the week 126. - [Triaging the Week 125](https://kravensecurity.com/triaging-the-week-125/): AI Agents & MCP Targeted // Riding the AI Hype Wave // Developers & Researchers Under Siege // Nation-State Espionage & Targeted Intrusions // The Browser & Identity Battleground in triaging the week 125. - [Why Your CTI Analyst Career Is Stuck (It's Not a Skills Problem)](https://kravensecurity.com/standing-out-as-a-cti-analyst/): Most people think breaking into cyber threat intelligence (CTI) is a skills problem. It is not. It is a signal problem. I came up through a managed security services provider (MSSP) security operations center (SOC), triaging alerts before I could even define a threat actor. I have since walked the path from SOC analyst to threat hunter to CTI analyst, and the biggest lesson from that climb is this: CTI is not an entry-level discipline.  The process of taking raw inputs, such as indicators of compromise (IOCs), packet captures (PCAPs), and open-source intelligence (OSINT), and turning them into intelligence that drives […] - [Triaging the Week 124](https://kravensecurity.com/triaging-the-week-124/): IABs & Backdoor Tradecraft // Vulnerabilities & Exploitable Infrastructure // Social Engineering & Trust Abuse // AI Supply Chain & Agentic Risks // Law Enforcement Wins & Phishing Evolution in triaging the week 124. - [Volt Typhoon: Hunting the Ghost Already Living in Your Network](https://kravensecurity.com/volt-typhoon-threat-profile/): Volt Typhoon hides inside your own tools and waits. Learn how this Chinese APT pre-positions in critical infrastructure and how to hunt it in your network. - [Triaging the Week 123](https://kravensecurity.com/triaging-the-week-123/): AI Both the Weapon and the Weak Link // Trusted Channels Weaponized // Covert Surveillance // Critical Exploits & Active Campaigns // The Future of Vulnerability Management in triaging the week 123. - [Triaging the Week 122](https://kravensecurity.com/triaging-the-week-122/): AI on the Offensive // The AI Layer as an Attack Surface // Poisoning the Supply Chain & Hunting Developers // Deception-Led Delivery & Trusted Infrastructure // Guarding the Access Layer in triaging the week 122. - [CTI for SMB: How Small Businesses Can Operationalize Threat Intelligence for Free](https://kravensecurity.com/cti-for-smb/): Learn how to build a threat intelligence program for your SMB using free tools like OTX and MISP. Get actionable CTI for SMBs this afternoon. - [Triaging the Week 121](https://kravensecurity.com/triaging-the-week-121/): The Supply Chain Siege // MFA Bypass & Identity-Based Intrusions // Evading Detection (Fileless, Stealth & Living-off-the-Land) // Critical Vulns & the Vanishing Patch Window // Social Engineering Remains Rampant in triaging the week 121. - [Triaging the Week 120](https://kravensecurity.com/triaging-the-week-120/): Developer Ecosystem Attacks // Critical Vulnerabilities Under Active Exploitation // Cloud, Identity & Data Breaches // APT & Nation-State Activity // AI Security, Malware Infrastructure & Takedowns in Triaging the Week 120 - [Detection Engineering in 2026: The Complete Lifecycle (Sigma, YARA, DaC & AI)](https://kravensecurity.com/detection-engineering-lifecycle/): Detection engineering is more than writing SIEM rules. Learn the 6-phase lifecycle, the detection-as-code model, and why identity is the new battlefield. - [Triaging the Week 119](https://kravensecurity.com/triaging-the-week-119/): The AI Arms Race Continues // Supply Chain & Open Source Ecosystem Poisoning // Platform, Website & AI Ecosystem Abuse // Critical Vulnerabilities // Persistence, Detection Failures & Major Breaches in triaging the week 119. - [Triaging the Week 118](https://kravensecurity.com/triaging-the-week-118/): AiTM & Identity Hijacking Wave // Supply Chain Compromise Continue // Cloud, Web & Infrastructure Exploitation // Banking Trojans & State-Sponsored Smokescreens in triaging the week 118. - [The Best CTI Certification Path: 4 Certs to Land Your First Threat Intelligence Role](https://kravensecurity.com/the-best-cti-certifications-for-beginners/): Cut through the noise. Discover the four CTI certifications that actually get you hired, in the right order, without wasting time or money. - [Triaging the Week 117](https://kravensecurity.com/triaging-the-week-117/): Social engineering & identity abuse // developer ecosystem under seige // AI weapon & target // network edge targeted // mass breaches & destructive outcomes in triaging the week 117. - [Triaging the Week 116](https://kravensecurity.com/triaging-the-week-116/): Critical intelligence exposes fast-moving RaaS operations, systemic AI/DevSecOps supply chain vulnerabilities, and covert nation-state evasion tactics hidden within your trusted enterprise services in triaing the week 116. - [MCP Servers for CTI in 2026: The Tools, the Risks, and What Comes Next](https://kravensecurity.com/mcp-servers-for-cti/): How MCP servers are transforming CTI workflows in 2026, which tools are worth your time, and how to secure the new attack surface they create. - [Triaging the Week 115](https://kravensecurity.com/triaging-the-week-115/): Attackers weaponized AI and compromised supply chains this week, exploiting zero-day flaws in Adobe and Nginx while exposing critical industrial control systems and cloud analytics platforms in triaging the week 115. - [Triaging the Week 114](https://kravensecurity.com/triaging-the-week-114/): Nation-states and ransomware groups target the software supply chain and critical infrastructure, LinkedIn spies on your browser, and GPUs under attack in triaging the week 114. - [Threat Profile: Scattered Spider](https://kravensecurity.com/threat-profile-scattered-spider/): One phone call brought down M&S and cost £300M. Here's who Scattered Spider is, how they operate, and the controls that stop them. - [Triaging the Week 113](https://kravensecurity.com/triaging-the-week-113/): Sophisticated social engineering, supply chain compromises, and human error have made platform trust and user vigilance the most critical lines of defense in triaging the week 113. - [Triaging the Week 112](https://kravensecurity.com/triaging-the-week-112/): Supply chain attacks, MFA bypasses, and AI-powered social engineering dominate the security landscape this week in triaging the week 112. - [Data vs Information vs Intelligence: A CTI Analyst's Guide to Communicating What Matters](https://kravensecurity.com/data-information-intelligence/): Learn the difference between data, information, and intelligence. Discover how CTI analysts can brief stakeholders in language that drives action. - [Triaging the Week 111](https://kravensecurity.com/triaging-the-week-111/): Critical security updates for Android and iOS, major flaws in Linux (CrackArmor), attacks using fake VPNs and hijacked GitHub repos, and the disruption of a massive 3-million device botnet in triaging the week 111. - [Triaging the Week 110](https://kravensecurity.com/triaging-the-week-110/): AI fuels wave of industrial-scale malware, forcing defenders to battle new threats on the cloud, mobile, and the abuse of legitimate tools in triaging the week 110. - [The F3EAD Intelligence Loop Explained: A Complete Guide 2026](https://kravensecurity.com/f3ead-loop/): Discover how to use the F3EAD intelligence loop to enhance your cyber threat intelligence processes and produce actionable insights in this complete guide. - [Triaging the Week 109](https://kravensecurity.com/triaging-the-week-109/): AI-native attacks, zero-day surges, and a global crackdown on violent cybercrime mark a week where trust is the ultimate vulnerability in triaging the week 109. - [Triaging the Week 108](https://kravensecurity.com/triaging-the-week-108/): AI-augmented attacks, state-sponsored RaaS, and blockchain C2 are defining the new cyber landscape in triaging the week 108. - [From IT to SOC to CTI Analyst: The 3-Stage Career Roadmap and Mindset Shifts](https://kravensecurity.com/it-to-soc-to-cti-analyst-career/): Want to become a CTI analyst? This guide maps the 3-stage pathway from IT support to SOC to cyber threat intelligence. Start your journey here. - [Triaging the Week 107](https://kravensecurity.com/triaging-the-week-107/): New AI-driven malware, a surge in supply chain attacks, and critical vulnerabilities found in major password managers in triaging the week 107. - [Triaging the Week 106](https://kravensecurity.com/triaging-the-week-106/): AI in the crosshairs: State-sponsored espionage, cloud worms, and supply chain attacks dominate in triaging the week 106. - [Triaging the Week 105](https://kravensecurity.com/triaging-the-week-105/): Supply chain attacks, AI-centric vulnerabilities, abused kernel drivers, and AI assistant marketplaces hit hard in triaging the week 105. - [Triaging the Week 104](https://kravensecurity.com/triaging-the-week-104/): Destructive nation-state attacks, new AI-weaponized malware, critical zero-day vulnerabilities, supply-chain attacks affecting NPM and PyPI, and 175K exposed Ollama AI servers in triaging the week 104. - [Triaging the Week 103](https://kravensecurity.com/triaging-the-week-103/): AI-coded malware, weaponized extensions, social engineering the help desk, and exploiting zero-days across critical infrastructure. All in this week's edition of triaging the week. - [Why Your CTI Team Can't Keep Up (And How Data Engineering for CTI Fixes It)](https://kravensecurity.com/data-engineering-for-cti/): Learn how data engineering for CTI can transform your threat intelligence team from reactive to proactive. A complete guide with actions. - [Triaging the Week 102](https://kravensecurity.com/triaging-the-week-102/): Quishing and Browser-in-the-Browser attacks steal credentials, exploitation of LLM services and automation platforms, a massive leak of BreachForums accounts, and urgent patches for Cisco and Fortinet in triaging the week 102. - [Triaging the Week 101](https://kravensecurity.com/triaging-the-week-101/): State-sponsored espionage, active exploitation of critical vulnerabilities in legacy hardware and popular software, and new malware campaigns targeting cloud services and user credentials in triaging the week 101. - [Triaging the Week 100](https://kravensecurity.com/triaging-the-week-100/): State-sponsored espionage using Windows Group Policy, new malware (SantaStealer, PyStoreRAT, DocSwap) distributed through phishing, fake GitHub repos, and compromised app stores in triaging the week 100. - [FlowViz: Turn 40-Page Threat Reports into Visual Attack Flows in Under a Minute](https://kravensecurity.com/flowviz-attack-flow-visualization/): Learn how FlowViz transforms threat reports into visual attack flows in seconds. Turn 40-page PDFs into MITRE ATT&CK-mapped diagrams with AI automation. - [Triaging the Week 099](https://kravensecurity.com/triaging-the-week-099/): Active exploitation of the critical "React2Shell" vulnerability, malicious VSCode extensions target developers, and urgent security warnings for Fortinet, Ivanti, and Docker Hub users in triaging the week 099. - [Triaging the Week 098](https://kravensecurity.com/triaging-the-week-098/): Critical supply chain vulnerabilities, compromised browser extensions, maximum-severity RCE flaws in React frameworks, and the rise of malicious AI models in triaging the week 098. - [Unified Kill Chain: The 18-Phase Framework That Actually Models Modern Attacks](https://kravensecurity.com/unified-kill-chain/): Discover why the Unified Kill Chain is the framework CTI analysts need. Learn how it fixes the Cyber Kill Chain's flaws and complements MITRE ATT&CK. - [Triaging the Week 097](https://kravensecurity.com/triaging-the-week-097/): WhatsApp metadata exposure affecting 3.5 billion accounts, a critical Grafana admin takeover vulnerability, a foiled insider threat at CrowdStrike, and a third-party breach impacting OpenAI in triaging the week 097. - [What is Detection Engineering? The Complete Career Guide for 2026](https://kravensecurity.com/what-is-detection-engineering/): Learn what detection engineering is, why it's the hottest cyber security career in 2025, and how to transition from SOC analyst to detection engineer. - [Triaging the Week 096](https://kravensecurity.com/triaging-the-week-096/): Automated AI cyberattacks, law enforcement actions against bulletproof hosting services, evolving threats from North Korean hackers, and new supply chain vulnerabilities in triaging the week 096. - [Information Disorder: A CTI Analyst's Guide to Fake News](https://kravensecurity.com/information-disorder-guide-for-cti-analysts/): Stop saying “fake news!” Learn how to classify information disorder professionally. A CTI analyst's guide to misinformation, disinformation, and malinformation. - [Triaging the Week 095](https://kravensecurity.com/triaging-the-week-095/): Glassworm malware returns, critical container escape flaws in runC, a side-channel attack on encrypted AI chats called 'WhisperLeak', and malicious NuGet packages with "time bomb" payloads in triaging the week 095. - [The CTI Analyst Roadmap: A Zero-to-Hero Guide with CTI Learning ](https://kravensecurity.com/cti-analyst-roadmap/): This CTI analyst roadmap turns chaos into clarity. It outlines the CTI learning resources, from SOC skills to strategic writing, to help you build your career. - [Triaging the Week 094](https://kravensecurity.com/triaging-the-week-094/): AI-powered malware and autonomous code-fixing agents, state-sponsored attacks, critical vulnerabilities, and sophisticated fraud networks in triaging the week 094. - [A Deep Dive on Tactical CTI and Operational CTI](https://kravensecurity.com/tactical-cti-and-operational-cti/): Stop just blocking IPs. Go beyond tactical CTI to master operational CTI. Learn to hunt adversary TTPs and build a truly predictive defense. - [Triaging the Week 093](https://kravensecurity.com/triaging-the-week-093/): Sophisticated phishing and ransomware campaigns, critical vulnerabilities in widely used software, and attacks on critical infrastructure make the headlines in triaging the week 093. - [Don't Be an Intel Island: Why CTI Sharing Communities Are a Superpower](https://kravensecurity.com/cti-sharing-communities/): Stop hoarding your intel! Learn why CTI sharing communities are a cyber security multiplier and the four communities you need to join right now. - [Triaging the Week 092](https://kravensecurity.com/triaging-the-week-092/): Cybercrime makes staggering income, ClickFix attacks and malicious extensions remain prevalent, and AI browsers targeted in traiging the week 092. - [Stop Wasting Time! How Jupyter Notebooks Can Automate Your CTI Work](https://kravensecurity.com/jupyter-notebook-for-cti/): Unlock the power of the Jupyter Notebook. Our guide for CTI analysts covers setup, API integration, and practical examples to streamline your workflow. - [Triaging the Week 091](https://kravensecurity.com/triaging-the-week-091/): SonicWall VPN, F5, Harvard, Cisco, and Oracle come under fire, Capita fined record-breaking amount by ICO, and even more malicious coding extensions in triaging the week 091. - [So You Want to Be a CTI Analyst? The Ultimate Career Guide](https://kravensecurity.com/how-to-become-a-cti-analyst/): Ready to become a CTI analyst? Our guide covers the essential skills, daily tasks, and a proven roadmap to help you land a job in cyber threat intelligence! - [Triaging the Week 090](https://kravensecurity.com/triaging-the-week-090/): Flaws in Redis, GoAnywhere, and AI browsers, Docker hardens images for everyone, and hackers target payroll in triaging the week 090. - [Taming the Data Beast: A Threat Hunter's Guide to Nushell](https://kravensecurity.com/threat-hunting-with-nushell/): Unleash the power of your command line with Nushell, the modern shell for cyber security professionals. Analyze data more efficiently with Nushell today! - [Triaging the Week 089](https://kravensecurity.com/triaging-the-week-089/): Attacks on SonicWall VPN, Gemini, Western Digital, Red Hat, Asahi, and Sudo, AI attacks become more popular, and Microsoft combats SVG phishing in triaging the week 089. - [Stop Drowning in Data: Build Your Own CTI Aggregator for Free](https://kravensecurity.com/cti-aggregator-inoreader/): Tired of information overload? Learn how to build a free CTI aggregator to centralize your threat intelligence feeds and stay ahead of attackers with Inoreader. - [Triaging the Week 088](https://kravensecurity.com/triaging-the-week-088/): Critical flaw in Microsoft Entra ID, impersonation galore on GitHub, Steam, and NPM, and ransomware disrupts major European airports in triaging the week 088. - [From Logs to Leads: A Practical Cyber Investigation of the Brutus Sherlock](https://kravensecurity.com/hack-the-box-brutus-sherlock-walkthrough/): Transform raw logs into leads in this practical cyber investigation guide. We solve the Hack the Box Brutus Sherlock and show you how to hunt down attackers. - [Triaging the Week 087](https://kravensecurity.com/triaging-the-week-087/): Supply chain attacks hit VSCode and NPM, new “FileFix” attacks, and Scattered Spider make a comeback in triaging the week 087. - [Triaging the Week 086](https://kravensecurity.com/triaging-the-week-086/): Hackers abuse iCloud and SVG images for phishing, AI-powered malware hits the scene, and a massive supply chain attack hits NPM in triaging the week 086. - [Triaging the Week 085](https://kravensecurity.com/triaging-the-week-085/): Russian APTs in the news again, massive data breaches at popular security companies, and AI weaponized by hackers in triaging the week 085. - [Beyond the Buzzwords: How to Measure Success Using CTI Metrics](https://kravensecurity.com/cti-metrics-to-measure-your-cti-program/): Struggling to demonstrate your CTI program success? This guide breaks down how to key operational, tactical, and strategic CTI metrics to measure success. - [Triaging the Week 084](https://kravensecurity.com/triaging-the-week-084/): Critical Docker and Citrix vulnerabilities, new AI attacks and AI-powered ransomware, and Salesforce customers get a nasty surprise in triaging the week 084. - [What is an Intelligence Product? A Complete Guide](https://kravensecurity.com/intelligence-product-guide/): What is a cyber threat intelligence product? This guide breaks down what an intelligence product is, with examples, and how you can create one in 4 steps. - [Triaging the Week 083](https://kravensecurity.com/triaging-the-week-083/): Colt and Workday were hit by cyber attacks, Microsoft, Okta, and PyPi beefed up security, and major password managers were hit by a clickjacking vulnerability in triaging the week 083. - [How to Generate Strategic Intelligence by Answering 20 Questions](https://kravensecurity.com/strategic-intelligence-in-20-questions/): Elevate your CTI analysis by learning how to create actionable strategic intelligence in this guide to the 20 essential questions you must answer. - [Triaging the Week 082](https://kravensecurity.com/triaging-the-week-082/): Linux malware targets Lenovo web cams, critical vulnerabilities in WinRAR and GPT-5, and new phishing attacks target Booking.com and Microsoft 365 Apps, in triaging the week 082. - [Structured Analytic Techniques: How to Analyze Threat Intelligence](https://kravensecurity.com/structured-analytic-techniques/): Master cyber threat intelligence with our guide to using structured analytic techniques (SAT). Overcome bias, improve your analysis, and make better decisions. - [Triaging the Week 081](https://kravensecurity.com/triaging-the-week-081/): Vulnerabilities in AI vibe coding tools, malware targets the Google Play store and WhatsApp devs, and new hacking tools hit the cybercrime market in triaging the week 081. - [Structured vs. Unstructured Threat Intelligence: The Ultimate Guide](https://kravensecurity.com/structured-unstructured-threat-intelligence/): Confused by threat intelligence formats? This guide breaks down the differences and importance of both structured and unstructured threat intelligence. - [Triaging the Week 080](https://kravensecurity.com/triaging-the-week-080/): Flaws in AI coding apps, major data breaches for Allianz and Tea Dating app, and Russian Aeroflot grounded by cyber attack in triaging the week 080. - [From Free to Enterprise: Threat Intelligence Platforms Explained](https://kravensecurity.com/threat-intelligence-platform/): Drowning in data? Discover how a Threat Intelligence Platform (TIP) can help. Explore the various types and learn how to select the right one for you. - [Triaging the Week 079](https://kravensecurity.com/triaging-the-week-079/): Supply chain attacks target NPM, vulnerabilities galore, and old malware adds new tricks in triaging the week 079. - [Acalvio ShadowPlex: A Powerful Platform Dedicated to Cyber Deception](https://kravensecurity.com/acalvio-shadowplex-cyber-deception/): Ready to outsmart attackers? Acalvio's ShadowPlex AI-powered cyber deception platform can stop emerging threats and provide high-fidelity intelligence. - [Triaging the Week 078](https://kravensecurity.com/triaging-the-week-078/): The high-profile attacks on Marks & Spencer, Co-op, and Harrods unraveled, AI flaws and misconfiguration run rampant, and Abacus dark web taken down in triaging the week 078. - [CTI Notetaking: How to Make Effective Notes and Documentation](https://kravensecurity.com/cti-notetaking-guide/): Elevate your analysis with our ultimate guide to CTI notetaking. Learn the principles, tools, and best practices to master notetaking for CTI. - [Data Collection Methods for CTI: How to Collect Data](https://kravensecurity.com/data-collection-methods-for-cti/): Unlock the secrets of cyber threat intelligence with our expert guide on data collection methods and learn to gather actionable intelligence. - [Triaging the Week 077](https://kravensecurity.com/triaging-the-week-077/): Vulnerabilities found in Bluetooth, Cisco UCM, and Anthropic AI; Scattered Spider shift targets; and big busts for Europol and FBI in triaging the week 077. - [Demystifying Source Reliability: How to Ensure Credible CTI](https://kravensecurity.com/source-reliability-and-information-credibility/): Master CTI source reliability. Our guide for analysts explains how to grade sources using the Admiralty Code to build actionable intelligence. - [Triaging the Week 076](https://kravensecurity.com/triaging-the-week-076/): New vulnerabilities, breaches, bypasses, and ClickFix attacks dominate the headlines in triaging the week 076. - [Triaging the Week 075](https://kravensecurity.com/triaging-the-week-075/): Surge in Malware Targeting Crypto Devs, AI Deepfake Scams Hit Instagram, and DPRK Hackers Target Zoom in triaging the week 075. - [Active Defense and Cyber Deception: Your Guide to Proactive Defense](https://kravensecurity.com/guide-to-active-defense-and-cyber-deception/): Learn how to flip the script on attackers in this comprehensive guide on active defense and cyber deception for cyber security analysts. ## Pages - [Tutor Certificate Verification](https://kravensecurity.com/tutor-certificate-verification/) - [Tutor Certificate](https://kravensecurity.com/tutor-certificate/) - [Business Consulting](https://kravensecurity.com/business-consulting/): Discover how cyber threat intelligence can bolster your cyber security posture and strengthen your business against emerging threats. - [Community Resources](https://kravensecurity.com/community-resources/): Want to learn other cyber security skills or tools? Check out these great training and tools from other reputable cyber security companies. - [Blog](https://kravensecurity.com/blog/): The Kraven Security blog is the ultimate resource for free content on cyber threat intelligence, threat hunting, and custom tooling. - [Checkout](https://kravensecurity.com/checkout/) - [Cart](https://kravensecurity.com/cart/) - [Instructor Registration](https://kravensecurity.com/instructor-registration/) - [Student Registration](https://kravensecurity.com/student-registration/) - [Dashboard](https://kravensecurity.com/dashboard/) - [Individual Coaching](https://kravensecurity.com/individual-coaching/): Elevate your skillset with our coaching and mentorship sessions. These will empower you to develop in-demand skills and accomplish short-term goals. - [Content Signup Success](https://kravensecurity.com/content-signup-success/): Thank you for signing up! We have sent you an email asking you to confirm your email address. Please verify your email to receive a notification whenever we drop new content. - [Weekly Newsletter](https://kravensecurity.com/weekly-newsletter-signup/): Archives - [Newsletter Signup Success](https://kravensecurity.com/newsletter-signup-success/): Thank you for signing up! We have sent you an email asking you to confirm your email address. Please verify your email to receive our weekly newsletter. - [Code of Conduct](https://kravensecurity.com/code-of-conduct/): Code of Conduct Kraven Security is dedicated to fostering a secure and inclusive educational environment, free from discrimination and harassment. To achieve this, all event attendees agree to the following rules without exception. This code of conduct applies to all live, recorded, written, verbal, and visual interactions. Rules of Conduct Professional Decorum: Conduct yourself professionally during all events. Non-Professional Attacks: Refrain from non-professional personal attacks against attendees or speakers. No Hate Speech: Avoid hate speech, offensive, or derogatory comments. Embrace diversity and welcome individuals from all backgrounds. Content Use: Do not record, reproduce, or share teaching content unless explicitly allowed. Note-taking […] - [GitHub Repositories](https://kravensecurity.com/github-repositories/) - [Paid Learning Resources](https://kravensecurity.com/learn2/paid-learning-resources/): Paid Learning Resources When you are ready to take your cyber security skills to the next level, our paid learning resources are here for you. They are expertly designed by industry professionals to provide you with the knowledge and skills you need to succeed, streamlined to fast-track your learning journey, and delivered with video and text to help you in whatever way you learn best. Coming Soon! We are hard at work creating a game-changing cyber threat intelligence 101 course that will take you from zero to hero. -> Expert insights -> Applied learning style -> Practical demonstrations -> Structured training […] - [Threat Hunting](https://kravensecurity.com/learn2/threat-hunting/): Previous slide Next slide Explore Our Free Threat Hunting Content Our threat hunting content will help you master the mysterious art of hunting down threats in the cyber realm. You will see how to create complex hunting queries, automate your threat hunting workflow, and create your own hunting tools. Start your learning journey now!​ Read All Join the Discussion Visit out Discord server to join the discussion on all our threat hunting content. We have a dedicated Threat Hunting forum where you can share your thoughts, learn from like-minded individuals, and discover more unique insight. Join Now Stay up-to-date whenever we […] - [Learning Resources](https://kravensecurity.com/learning-resources/): Start your learning journey today using our FREE learning resources. This includes cyber threat intelligence, threat hunting, and custom tooling content. - [Home](https://kravensecurity.com/): Kraven Security transforms cyber security from reactive to proactive, empowering individuals and businesses to leverage Cyber Threat Intelligence (CTI) effectively. - [Blog3](https://kravensecurity.com/blog3/) - [Frequently Asked Questions](https://kravensecurity.com/frequently-asked-questions/): Frequently Asked Questions General What is Kraven Security? Kraven Security is a cyber security consulting and teaching company who specializes in cyber threat intelligence. Our official website is https://kravensecurity.com and we adhere to the laws of the United Kingdom. We have expertise in threat intelligence, threat hunting, and custom tooling, and aim to share these with students all other the world through our active blog for free. We also offer services around these topics for prospective students and organizations who want to elevate their skills or threat intelligence capabilities. Where can I find updates about Kraven Security? We are active on […] - [Terms & Conditions](https://kravensecurity.com/terms-conditions/): Terms & Conditions Who is Kraven Security Kraven Security is a cyber security consulting and teaching company specializing in cyber threat intelligence. Our official website is https://kravensecurity.com, and we adhere to the laws of the United Kingdom. Terms and Conditions Kraven Security disclaims responsibility for any errors, omissions, or inaccuracies in content. All our products and services are sold on an “as-is” basis without any implied or expressed warranty. In fulfilling its mission to educate the public on cybersecurity, Kraven Security may discuss and analyze malicious and illegal activities. However, it unequivocally does not endorse or support any illegal activities by […] - [Services](https://kravensecurity.com/services/): Services Our free content will teach you everything you need to master cyber threat intelligence and hunting. If you want tailored advice to propel your transformation, check out the services we offer and get in touch. Individual Want to learn the skills required to excel at cyber threat intelligence? Business Looking to build, improve, or assess your cyber threat intelligence capabilities? - [Learn2](https://kravensecurity.com/learn2/): Learning Resources We have a range of learning resources for you to choose from. This includes blog series, free mini-courses, and comprehensive paid courses on cyber threat intelligence, threat hunting, and custom tooling. The FREE Stuff Quality content for those who are on a budget or tyring before they buy. Game Changing Stuff When you’re ready to take your skills to the next level, our paid training options have you covered. - [Privacy Policy](https://kravensecurity.com/privacy-policy/): Privacy Policy Who is Kraven Security Kraven Security is a cyber security consulting and teaching company who specializes in cyber threat intelligence. Our official website is https://kravensecurity.com and we adhere to the laws of the United Kingdom. Personal Data Collection Comments When visitors leave comments, we collect data from the comments form, the visitor’s IP address, and browser user agent string for spam detection. An anonymized string created from the email address may be provided to the Gravatar service for profile picture display. Media If you upload images, avoid including embedded location data (EXIF GPS) as visitors can download and extract […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/kravensecurity.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)