Micah Babinski·Nov 26, 2025Detecting Malicious ArcGIS Server Object ExtensionsFinally, the GIS/Detection Engineering Crossover Episode!
Micah Babinski·Sep 9, 2024Dive into Sigma Correlation RulesAnd go hunting for Cicada3301 ransomware behaviors in the process
Micah Babinski·Oct 30, 2023Hunting G-G-G-GhostTasks!Detecting a Spooktacular Persistence ProcedureA response icon1A response icon1
Micah Babinski·Oct 16, 2023It’s Always DarkGate Before the DawnDetecting DarkGate, an Emerging Malware Threat
Micah Babinski·Aug 1, 2023Search-ms, WebDAV, and ChillDetecting a [Re-]emerging Initial Access MethodA response icon1A response icon1
Micah Babinski·May 26, 2023Button-Pusher to MasterBuilder: Automating SIEM WorkflowsBuild Confidence and Skill in SIEM AutomationA response icon1A response icon1
Micah Babinski·Apr 17, 2023Brace for Impacket!Detecting a Red Team (and Threat Actor) FavoriteA response icon1A response icon1
Micah Babinski·Jan 31, 2023Detecting OneNote (.One) Malware DeliveryI opened a dozen malicious OneNote files and clicked on every link so you don’t have to
Micah Babinski·Dec 13, 2022Finding the Gap: How Curiosity and Creativity Drives Threat DetectionLet the Real World be your Lab with Mitre ATT&CK, Atomic Red Team, and Sigma