NEXUSNIMBUS
  • Research
  • Projects
  • Games
  • Tools
  • Contact
  • About
// archive

All Posts

ACTIVE

Network Detection: What DNS, Proxy and Flow Logs Reveal That Endpoints Miss

Endpoint telemetry stops at the devices you manage. Network data covers everything that talks, including the printer, the contractor's laptop and the appliance nobody can install an agent on.

ACTIVE

Living Off the Land: Detecting Attackers Who Use Your Own Tools

When the attacker's toolkit is already installed, signed by Microsoft and trusted by your allowlist, malware detection has nothing to detect. The answer is not another signature — it is…

ACTIVE

Detection Engineering 101: Writing Detections That Survive

Moving from brittle IOCs up the Pyramid of Pain to behavior-based detections that outlast attacker infrastructure.

ACTIVE

The Windows Event Logs That Actually Matter for Detection

Windows emits an overwhelming volume of events and almost none of it is useful by default. A field guide to the specific event IDs worth collecting, what each one proves,…

ACTIVE

Mapping Your Defenses to MITRE ATT&CK (Without Coverage Theater)

Turning the ATT&CK matrix from a poster on the wall into a prioritized, threat-informed defensive roadmap.

© 2026 NEXUSNIMBUS.COM — ALL SYSTEMS OPERATIONAL
  • Privacy Policy
  • Research Projects Tools Contact