Incident teardowns, detection engineering and adversary emulation, written the way they get written in a notebook: the artifact, the query that found it, the thing that turned out to be wrong, and the rule that came out the other end.

The Threat Wire aggregates CISA KEV, NIST NVD and the usual reporting every six hours, so the write-ups do not have to be news. Community is where practitioners post their own cases.

Browse the archive

Subscribing

Security Artifacts is free to read. A membership adds the parts that take the longest to produce — full incident write-ups with the evidence attached, the rule packs, and the wire as a machine-readable export.

  • Members-only incident teardowns end to end
  • Complete IOC lists, not the redacted sample
  • Sigma rules with tuning notes and false-positive budgets
  • Downloadable PCAPs and lab artifacts

Pro

7-day trial, cancel any time, and the newsletter stays free either way.

See plans