Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

LimaCharlie 101: EDR deployment, detection rules, and threat intelligence

This workshop will cover the basics of the LimaCharlie SecOps platform. You will learn how to deploy EDR agents, gather additional telemetry and write detection and response rules, and integrate threat intelligence and YARA rules to detect and mitigate threats. Key Learning Objectives: Endpoint Detection and Response (EDR) Agent Deployment and Management: Learn the best practices for deploying LimaCharlie EDR agents across diverse environments. Understand the various deployment methods, agent configurations, and how to effectively manage agent health and status at scale.

When the Attacker Is the AI: What the OpenAI Sandbox Escape Means for Threat Intelligence Teams

An OpenAI agent broke out of its test sandbox and autonomously breached Hugging Face with no human direction, an incident both companies called unprecedented. CYJAX examines why this doesn't fit existing threat actor categories, maps it to the standard attack lifecycle, and outlines three additions CTI teams should make to their collection plans and PIRs to track autonomous offensive tooling before it hits their own network. On 16th July 2026, Hugging Face disclosed that it had been breached.

Cyber Threat Intelligence: How to Build a Practical Programme for Your SOC

As cyber dangers get more sophisticated and messy, company SOCs can't simply keep playing defense. An effective IT security strategy today includes hunting malicious agents down before they strike. Modern organizations need a thorough grasp of the tactics, techniques, and procedures used by industry-specific adversaries.

AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs

Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and prioritization so analysts spend time on decisions, not data wrangling.

Data Flow Diagrams in Threat Modeling: From Whiteboard Sketch to Living Security Artifact

Most threat modeling sessions that fail do so before anyone has said the word "threat." They fail because the team is arguing about how the system actually works. One engineer thinks authentication happens at the gateway; another is certain it happens in the service. Nobody can point to a shared picture, so the conversation drifts into architecture archaeology and the security questions never get asked.

The MemcycoFM Show: Ep 27 - What Is Agentic Threat Intelligence?

In the recently published blog from Memcyco titled "What Is Agentic Threat Intelligence?", we discussed agentic threat intelligence as an emerging CTI model. Bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.