RESOURCES

Field notes from the SOC.

Practitioner writing on MDR, SIEM operations, identity threat detection, threat advisories, and what running an actual 24/7 SOC teaches you. No fluff.

ALL POSTS · 29

Latest writing.

AI & Detection · 11 min

The AIDR Architecture: A Protection Map for Enterprise AI

How CrowdStrike AIDR inspects AI traffic across seven layers — the collector map, the Layer 5 policy engine, and the roadmap. A practitioner walkthrough.

2026-07-20
AI & Detection · 9 min

AIDR: AI Detection and Response, Explained for CISOs

AIDR is runtime security for AI systems: detecting and stopping agent threats as they execute. What it covers, and why existing tools miss it.

2026-07-18
AI & Detection · 11 min

Who Watches the Agent? Deploying CrowdStrike AIDR Across Claude Code, MCP, and the Browser

CrowdStrike AIDR across Claude Code hooks, the MCP proxy, and the browser — what each collector sees, and what it can't. By QMasters CTO Gregori Nazarovsky.

2026-07-17
AI & Detection · 12 min

AI and Detection Engineering: The Instrument, Not the Author

AI belongs in detection engineering as instrument, not author — across QRadar, Splunk, and CrowdStrike. By QMasters CTO Gregori Nazarovsky.

2026-07-16
AI & Detection · 10 min

AI, CrowdStrike MCP, and RTR: Real-Time Incident Response Across 100+ Machines

How AI plus CrowdStrike's read-only MCP and RTR run incident response across 100+ machines — 100GB+ of remote triage, with humans authorizing every action.

2026-07-15
AI & Detection · 8 min

Model Context Protocol for Security Teams: How AI Agents Ask, Investigate, Summarize, and Spot Trends

How SOC teams use MCP to ask, investigate, summarize, and spot trends across security tools — by QMasters CTO Gregori Nazarovsky.

2026-07-14
Threat Intelligence · 7 min

FortiOS SSL-VPN Zero-Day (CVE-2022-42475): What We Learned

Three years after CVE-2022-42475 hit FortiOS SSL-VPN, the playbook for handling vendor zero-days hasn't changed. Here's the IOC pattern, detection logic, and the operating model that catches the next one.

2026-04-15
Threat Intelligence · 6 min

Vendor Zero-Day Response: A 60-Minute Playbook

When a vendor like Fortinet, Cisco, F5, or Aruba publishes a critical advisory, the next 60 minutes determine your exposure. Here's the structured playbook QMasters' SOC runs.

2026-04-08
Incident Response · 10 min

Incident Response: The First 24 Hours, Done Right

What happens in the first 24 hours of an incident determines whether it stays contained or becomes a board-level event. Here's the operational playbook QMasters' IR team runs — minute by minute.

2026-04-02
Awareness & Training · 7 min

Awareness Training That Actually Works: Beyond the Annual Phishing Test

Most security awareness programs are compliance theater. The few that change behavior share a structural shape — short, role-targeted, behaviorally measured, and built around real attack patterns. Here is how QMasters runs awareness training as an operational control, not a checkbox.

2026-03-26
Threat Intelligence · 8 min

SysJoker Malware: From C++ Backdoor to Rust-Based Stealth

SysJoker has quietly evolved from a 2021 C++ backdoor into a Rust-based, multi-platform stealth tool. Here's what changed, why Rust matters, and how QMasters' SOC hunts for it today.

2026-03-22
Cloud Security · 8 min

SSPM Explained: SaaS Security Posture Management for Microsoft 365 and Google Workspace

SaaS Security Posture Management (SSPM) closes the gap between IT-managed SaaS and the security controls actually applied to it. Here is what SSPM is, why Microsoft 365 and Google Workspace deserve their own posture program, and the QMasters baseline for both.

2026-03-12
SIEM & Detection · 7 min

Windows Event Collection for QRadar: From WinCollect 7 to Today

Windows event collection has changed substantially since WinCollect 7. Here's the practical guide to current architecture, sizing, and the alternatives worth considering.

2026-03-10
Cloud Security · 11 min

CNAPP in 2026: Bringing CSPM, CWPP, and AI Detection Under One Roof

CNAPP started as a Gartner acronym and turned into the only practical way to secure cloud workloads at scale. Here is what CNAPP is in 2026, the mistakes that make it expensive, and the operating model QMasters runs across AWS, Azure, and GCP.

2026-02-26
Cloud Security · 8 min

Modern Vulnerability Management: From CVSS Lists to Exposure Management

Patching by CVSS score doesn't work anymore. The shift to exposure management — context, exploitability, business impact — is the single most important VM change of the decade.

2026-02-25
Managed SOC & MDR · 8 min

CrowdStrike Fusion SOAR: Building Workflows That Actually Save Analyst Time

CrowdStrike's Fusion SOAR has matured into a serious workflow platform. Here are the four playbooks every Falcon-using SOC should have running, and the design rules that keep them maintainable.

2026-02-18
Detection & Response · 8 min

Identity Threat Detection & Response (ITDR): Why Identity Is the New Endpoint

ITDR closes the gap between IAM (which decides who can log in) and EDR (which watches the endpoint). Here is why every modern attack now runs through identity, what ITDR actually does, and how QMasters operationalizes it on CrowdStrike Falcon Identity Protection.

2026-02-12
Incident Response · 10 min

Ransomware: The First 24 Hours Survival Guide

What to do in the first 24 hours of a ransomware attack — containment, communication, decision points, and the mistakes that turn bad days into catastrophic weeks.

2026-01-30
Threat Intelligence · 7 min

Living off the Land Attacks: Why Your AV Won't See Them

Living-off-the-Land (LotL) attacks use built-in OS tools instead of malware. They're harder to detect, harder to block, and they're now the dominant pattern in advanced intrusions.

2026-01-28
Strategy & MSSP · 11 min

Building a SOC: A 90-Day Playbook for Mid-Market Security Leaders

A realistic 90-day playbook for mid-market CISOs building or rebuilding a Security Operations Center — what to deploy, what to outsource, what to defer.

2026-01-28
SIEM & Detection · 10 min

CrowdStrike Next-Gen SIEM vs Legacy SIEM: A Migration Decision Framework

Should you migrate from QRadar, Splunk, or ArcSight to CrowdStrike Next-Gen SIEM? An honest framework — when it makes sense, when it doesn't, and what migration actually costs.

2026-01-26
Threat Intelligence · 8 min

DailyIOC: How Proactive IOC Blocking Stops Attacks Before Detection Fires

DailyIOC is QMasters' curated threat intelligence operation — 250K+ daily IOCs filtered to high-confidence indicators that get pushed into customer firewalls, EDR, DNS, and email gateways before alerts are needed.

2026-01-23
Strategy & MSSP · 7 min

What 'Unlimited MDR' Actually Means: Reading the Fine Print

Unlimited MDR sounds great on a slide. Behind the marketing, scope, response actions, and incident response are where vendors hide the real limits. Here's how to decode the offer.

2026-01-22
Strategy & MSSP · 9 min

Flat-Rate MDR vs Per-EPS SIEM: Why the Pricing Model Decides Your Security Outcome

Per-EPS pricing punishes visibility. Flat-rate MDR aligns vendor incentives with detection. Here's how to compare honestly — and why most CISOs are quietly switching.

2026-01-20
SIEM & Detection · 8 min

Deception Technology in 2026: Why Modern SOCs Are Bringing Honeypots Back

Modern deception is not 1990s honeypots. Decoy assets, tokens, and breadcrumbs produce zero-false-positive alerts that catch insider threats and dwell-time adversaries — when deployed correctly.

2026-01-17
SIEM & Detection · 9 min

The QRadar SIEM Audit: A Practical Checklist Before You Renew

A no-vendor-spin audit framework for QRadar deployments — health checks, content coverage, log source quality, license efficiency, and the questions to ask before renewal.

2026-01-16
SIEM & Detection · 8 min

Detecting APTs with the QRadar Suite: What Actually Works in 2026

Modern APT detection in QRadar Suite — why generic correlation rules fail, the four detection layers that actually catch nation-state tradecraft, and how QMasters tunes them at scale.

2026-01-15
SIEM & Detection · 7 min

DNS Monitoring: The Cheapest, Highest-Value Detection You're Not Doing

DNS traffic is the most under-used detection surface in most environments. Here's why, what to monitor, and the patterns that catch malware C2, exfiltration, and shadow IT.

2026-01-14

Visit our homepage, dig into our team, or check out upcoming events next.

READY WHEN YOU ARE

Want this in your inbox? Talk to us.

No newsletter form yet. If you want our advisories direct, ask a SOC engineer in the next call.

F-003 · CONSULTATION

Book 30 minutes. No slides.

A real working session with a SOC engineer — bring your alerts.