Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

LevelBlue Blog

Discover expert insights on the latest cybersecurity trends, challenges, and best practices shaping the industry today.

circleradial-blogs

LevelBlue Strengthens Cyber Resilience for Australian Critical Infrastructure with New Sydney SOC

August 27, 2026

Stay Informed

Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.

LevelBlue and SentinelOne: Advancing Integrated, Intelligence‑Driven Security Operations

March 24, 2026 | Bob McCullen

Today, I’m excited to share news that represents a major step forward in how ...

The Benefits of Sentinel’s Migration to the Unified Defender XDR Portal Through Security, Operational, and Commercial Lenses

December 26, 2025 | James Kucan

A SOC Toolbelt: Best Practices for Security Operations

August 07, 2025 | Nikki Stanziale

A SOC Toolbelt

Stories from the SOC – ClickFix and Chill, Now Here’s the Ransomware Bill

June 18, 2025 | Anthony Alvarado

Background

Stories from the SOC: Caught in the Trap: Detecting and Defending Against RaccoonO365 Phishing Campaigns

January 17, 2025 | Julius Charles, Alejandro Prada, and Josh Gomez

Executive Summary In September 2024, LevelBlue conducted a comprehensive threat ...

How Microsoft E5 Security Helps Protect Healthcare and Patient Data

October 10, 2024

In the healthcare industry, safeguarding patient data is not just a regulatory ...

Stories from the SOC - Sowing the Seeds of Cybercrime: The Credential Harvester

August 08, 2024 | Sean Shirley

Executive Summary Cyber attackers are constantly innovating new ways to ...

Navigating the Cybersecurity Landscape: A Deep Dive into Effective SIEM Strategies

July 02, 2024 | Sam Bocetta

The content of this post is solely the responsibility of the author. LevelBlue ...

Introduction to Software Composition Analysis and How to Select an SCA Tool

April 17, 2024 | Alex Vakulov

The content of this post is solely the responsibility of the author. LevelBlue ...

The modern next gen SOC powered by AI

February 21, 2024 | Matt Mui

AI is among the most disruptive technologies of our time. While AI/ML has been ...

DarkGate malware delivered via Microsoft Teams - detection and response

January 30, 2024 | Peter Boyle

Executive summary While most end users are well-acquainted with the dangers of ...

Cybersecurity operations in 2024: The SOC of the future

January 17, 2024 | Theresa Lanowitz

This is part two of a three-part series written by LevelBlue evangelist Theresa ...

Applying an intelligence-based approach to Cybersecurity; SIEM and dark web monitoring

November 06, 2023 | Chris Mark

“History repeatedly has demonstrated that inferior forces can win when leaders ...

Stories from the SOC  - The case for human response actions

February 23, 2023 | Edwardo Rodriguez

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - RapperBot, Mirai Botnet - C2, CDIR Drop over SSH

January 31, 2023 | Emine Akbulut

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC: Fortinet authentication bypass observed in the wild

November 14, 2022 | Amer Amer

Executive summary: Fortinet’s newest vulnerability, CVE-2022-40684, allowing ...

Stories from the SOC – Credential compromise and the importance of MFA

August 08, 2022 | Evan Carey

Stories from the SOC is a blog series that describes recent real-world security ...

How can SOC analysts use the cyber kill chain?

July 07, 2022 | Shigraf Aijaz

This blog was written by an independent guest blogger.

Stories from the SOC - Detecting internal reconnaissance

June 27, 2022 | Nathan Vail

Stories from the SOC is a blog series that describes recent real-world security ...

Suspicious behavior: OTX Indicator of Compromise - Detection & response

May 25, 2022 | Julius Charles

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - Persistent malware

May 16, 2022 | Adam Vertuca

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - Command and Control

May 09, 2022 | Robert Dean

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - Lateral movement using default accounts

April 19, 2022 | Robert Dean

Stories from the SOC is a blog series that describes recent real-world security ...

Working with MSSPs to optimize XDR

March 08, 2022 | Michael Vaughn

Businesses today have many tools in their security stack and security teams ...

Stories from the SOC - Inactive Account Exploitation

January 24, 2022 | Alex Galindo

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - Powershell, Proxyshell, Conti TTPs OH MY!

November 10, 2021 | Josh Gomez

Stories from the SOC is a blog series that describes recent real-world security ...

Stories from the SOC - Data exfiltration

October 11, 2021 | Julius Charles

Stories from the SOC is a blog series that describes recent real-world security ...