Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ten Black Hat NOCs and counting: Corelight sees it all

Whenever I come back from a Black Hat NOC, people always ask the same question: “So, what did you see?!” They understand how unique it is to have access to the detailed logs generated by an NDR overseeing the network traffic of a conference with thousands of attendees. There is always something to see. There are always stories that come out of the packets; those stories evolve into patterns, and the patterns offer the gift of lessons.

Cut Through the Noise: Learn How to Spot the Threats That Matter

Security teams today face an overwhelming volume of alerts, making it increasingly difficult to distinguish genuine threats from everyday noise. As attackers become more adept at blending into legitimate activity, organizations need smarter ways to prioritize, investigate, and respond.

Sophos Firewall v22 MR2 is now available

Sophos Firewall v22 MR2 is now available AI app control, PQC detection, enhanced Chromebook support, and more. Sophos Firewall v22 bolstered Secure by Design, taking it to a whole new level with major updates to the architecture and new features like the Health Check to help identify high-risk configurations. Sophos Firewall v22 MR1 added several enhancements, including a new set of NDR detections for active threats.

Sophos named a 2026 Gartner Peer Insights Customers' Choice for Email Security

Sophos named a 2026 Gartner Peer Insights Customers’ Choice for Email Security Sophos’ first ever recognition as a Customers’ Choice for Email Security. Sophos has been named a 2026 Gartner Peer Insights Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for Email Security. This marks Sophos’ entry into the report, as well as Sophos’ first ever Customers’ Choice distinction for Email Security.

Unmasking BitRAT's C2 over HTTPS

BitRAT is a potent and versatile Remote Access Trojan (RAT) commonly sold on underground forums. Its popularity stems from a robust feature set and an emphasis on stealth, allowing it to evade detection by hiding command-and-control (C2) communications over seemingly benign protocols. This makes traditional detection methods more challenging. By examining the subtle artifacts it leaves behind, even in encrypted traffic, defenders can expose these elusive threats.

How Do You Get Hacked With Zero Malware?

Everyone remembers WannaCry. WantToCry sounds like the same thing. It isn't. It encrypts your files remotely over SMB using nothing but stolen credentials and right now 1.5 million devices are sitting exposed on the public internet. In this episode we break down how remote ransomware works, why your antivirus and EDR never see it coming and what caught it in our Sophos telemetry.

From days of training to three better rules in a minute

A few years ago, I was part of a team responding to a high-profile security incident. After the incident was resolved, I was given a list of NDR rules to add to my firewalls. The issue was that the rules were not made for Suricata, the IDS I was using in this position at that time, so they generated false positives. With all that extra noise, I made it my goal to eliminate that excess noise.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 2 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.