Blog Entries

21. 07. 2026 Patrick Di Fazio Offensive Cloud Security, Offensive Security, Red Team, SEC4U

What Cloud Security Posture Management Actually Checks, and What It Doesn’t

Cloud Security Posture Management describes a category of tools that inspect cloud environments for configuration problems like public storage, overly broad IAM permissions, disabled logging, and missing encryption. The category includes open-source projects like Prowler and ScoutSuite, as well as commercial platforms. Despite different pricing models and interfaces, they solve the same underlying problem in…

Read More
20. 07. 2026 Marco Fazio Blue Team

Inside Password Attacks: A SOC Perspective

The View from the SOC From inside the SOC, authentication traffic never really stops. Most of it is ordinary business: people signing in, services renewing sessions, or developers moving between tools. Mixed into that stream is something far less ordinary: repeated, automated attempts to become someone else. That’s why identity work sits so close to…

Read More
03. 07. 2026 Francesco Pavanello AI, SEC4U, Threat Intelligence

The AI Cyber Attacks Explosion in 2026: Emerging Threats

The first half of 2026 has witnessed the transition of artificial intelligence from an experimental playground into a cyber warfare domain. In fact, threat actors have shifted from basic prompting toward highly automated, multi-stage operations. This shift is characterized by a bifurcation of threats. On one side, attacks exploiting inherent AI vulnerabilities and architectural boundaries,…

Read More
25. 06. 2026 Daniel Degasperi Blue Team, Log-SIEM, SEC4U, Threat Intelligence

LOLDrivers Is More Than a Simple List: A New Approach to BYOVD Detection

1. Introduction The abuse of vulnerable drivers has become an increasingly common technique adopted by attackers to bypass modern security controls. This attack pattern, commonly referred to as Bring Your Own Vulnerable Driver (BYOVD), consists of loading legitimately signed but vulnerable drivers into the operating system in order to gain kernel-level privileges, disable security products,…

Read More
04. 06. 2026 Patrick Di Fazio Offensive Security, Red Team, SEC4U

Purple Teaming as a Continuous Improvement Model

In cybersecurity, the gap between what we think we can detect and what we actually detect is often wider than we expect. Tools are configured, rules are written, playbooks are drafted, and yet, when a real attack unfolds, the telemetry is incomplete, the alerts are noisy, and the response is slower than it should be….

Read More
03. 06. 2026 Matteo Lorenzini SATAYO, SEC4U, Threat Intelligence

The Hidden Threat of Subdomain Takeovers

As a Cyber Threat Intelligence (CTI) Analyst, my daily work often involves analyzing suspicious domains that look like our clients’ brands. One of our goals is to prevent phishing campaigns and brand abuse. We usually hunt for external threats like typosquatting. However, sometimes the most dangerous threat comes directly from the legitimate infrastructure within the…

Read More
20. 05. 2026 Marco Fazio Automation, Blue Team, SEC4U

Device Isolation with SOAR

SOAR for Controlled Response SOAR is often described in broad terms: orchestration, automation, response, integration. That’s true, but it can also feel vague. A simpler way to explain it is this: SOAR helps a SOC turn a decision into action without repeating the same manual steps every time. This matters most when the action is…

Read More
11. 05. 2026 Alessio Dallaporta Blue Team, SEC4U

Bridging The Gap

Why a Purple Team Program Makes Cybersecurity More Effective In today’s cybersecurity landscape, having defensive tools in place is no longer enough. Firewalls, SIEM platforms, detection rules, playbooks, and threat intelligence feeds are all essential components, but the real question is this: how well do they actually perform under realistic attack conditions? This is where…

Read More
22. 04. 2026 Simone Ragonesi Offensive Security, Red Team, SEC4U

The Ghost in the Kernel Machine

There is a technology inside modern Linux systems that: It can do all of this (and much more) without the need of kernel modules;that technology is eBPF. The aim of this article is to provide an overview of the technology, present several use cases, and address potential misuse from an offensive security perspective. A Bit…

Read More
23. 03. 2026 Simone Ragonesi Offensive Security, Red Team, SEC4U

Writing High Quality Pentesting Reports

A pentest is only as valuable as the report that comes out of it. You can find critical vulnerabilities, chain exploits creatively, and demonstrate full infrastructure compromise, but if your report is unclear, overly technical, or poorly structured, its impact will be limited. A strong pentesting report bridges the gap between technical discovery and business…

Read More
23. 03. 2026 Alessio Dallaporta Blue Team

Inside Elastic Security Detection Rules: Internal Structure & Upgrade Mechanics

A Rule Is More Than a Query In modern detection engineering, a rule is often misunderstood as just a query that triggers alerts. In reality, within Elastic Security, a detection rule is a structured, versioned, and lifecycle-managed object that goes far beyond simple query logic. Understanding this structure is essential for anyone operating in a…

Read More
11. 03. 2026 Daniel Degasperi Blue Team, Log-SIEM, SEC4U, Threat Intelligence

From Static Lists to Threat Intelligence: Better Domain Detection in Elastic

A scalable approach to detecting malicious domains using Threat Intelligence and Indicator Match Rules One of the most common techniques used in phishing and initial access campaigns is the creation of domains that closely resemble legitimate ones. Attackers exploit typosquatting, homograph attacks, and brand impersonation to deceive users and steal credentials. For a Security Operations…

Read More
04. 02. 2026 Massimo Giaimo Threat Intelligence

From RAMP to RehubCom?

There’s been a lot of talk in recent days about the seizure of the underground forum RAMP. There’s little to add to this issue, which has already been extensively written about. An excellent summary is available in this BleepingComputer article. What I’d like to highlight in this article, however, is how the main players in…

Read More
27. 01. 2026 Simone Ragonesi Automation, Development, DevOps, Offensive Security, Red Team, SEC4U

Architecting a Portable Red Team Engine

This is the first article in the RTO series The Problem Red team and penetration testing activities are full of repetition: the network scans, reconnaissance, OSINT collection, and routine validation tasks are all necessary, but they’re also time-consuming and error-prone when executed manually. Over time, most teams end up with a zoo of scripts, half-maintained…

Read More
11. 01. 2026 Simone Ragonesi Blue Team, Offensive Security, Red Team, SEC4U

Purple Teaming is a MUST, not a PLUS

In modern security programs the silos between offensive and defensive teams is no longer sustainable: attackers iterate faster, tooling evolves daily, and detection gaps are exploited in minutes, not months. In this environment purple teaming is not an optional maturity enhancement, but it becomes a foundational requirement for organizations that take risk management seriously. Purple…

Read More

Archive