NEXUSNIMBUS
  • Research
  • Projects
  • Games
  • Tools
  • Contact
  • About
// research_archive

SOC Research Papers

RESEARCH
2026-07-04

Living Off the Land: Detecting Attackers Who Use Your Own Tools

When the attacker's toolkit is already installed, signed by Microsoft and trusted by your allowlist, malware detection has nothing to detect. The answer is not another signature — it is…

Read full paper →
RESEARCH
2026-07-03

The First Hour: A Practical Incident Response Playbook

The first hour of an incident decides how much of the investigation is still possible later. A guide to verifying, scoping and containing without destroying the evidence you will need.

Read full paper →
RESEARCH
2026-07-02

Identity Is the New Perimeter: Detecting Account Takeover

Credential stuffing, password spraying, and MFA-bypass phishing — and the sign-in signals that catch them.

Read full paper →
RESEARCH
2026-07-01

Detection Engineering 101: Writing Detections That Survive

Moving from brittle IOCs up the Pyramid of Pain to behavior-based detections that outlast attacker infrastructure.

Read full paper →
RESEARCH
2026-06-30

The Windows Event Logs That Actually Matter for Detection

Windows emits an overwhelming volume of events and almost none of it is useful by default. A field guide to the specific event IDs worth collecting, what each one proves,…

Read full paper →
RESEARCH
2026-06-28

Mapping Your Defenses to MITRE ATT&CK (Without Coverage Theater)

Turning the ATT&CK matrix from a poster on the wall into a prioritized, threat-informed defensive roadmap.

Read full paper →
RESEARCH
2026-06-25

Password Cracking in 2026: Entropy, GPUs, and the Passkey Endgame

What actually makes a password hard to crack, why length beats complexity, and where passkeys leave attackers.

Read full paper →
RESEARCH
2026-06-21

Static Malware Triage: Reading a Sample Before You Detonate It

What file type, hashes, strings, and PE imports reveal about a suspicious binary — no sandbox required.

Read full paper →
RESEARCH
2026-06-18

Anatomy of a Phishing URL: How Attackers Weaponize Web Addresses

The structural tricks behind malicious links — and the heuristics that catch them before a user clicks.

Read full paper →
RESEARCH
2026-06-13

Anatomy of a Ransomware Attack: From Initial Access to Extortion

Walking the modern ransomware kill chain — how operators get in, move, steal, and encrypt, and where defenders can break the chain.

Read full paper →
« PREV 1 2 3 NEXT »
© 2026 NEXUSNIMBUS.COM — ALL SYSTEMS OPERATIONAL
  • Privacy Policy
  • Research Projects Tools Contact