top of page
Blog, Press, Updates and More.


Project Beat
"Testing detection isn't about outsmarting the defenders; it's about ensuring the defense can see what matters." đ§Why double down on Linux security right now? With the sheer volume of Linux vulnerabilities hitting the headlines this year, resting on our security posture wasn't an option. Cybersift needed to know: When an attacker lands on our clientsâ Linux servers, can our SIEM actually see what's happening beneath the noise? That was when we launched Project BEAT, a joint
Katrina Fenech & Brandon Spiteri
Aug 312 min read
Â
Â


Inside the Enterprise Risk Profile of Residential Proxies
On July 2nd, 2025, a user known as 'Admirable-Raccoon597' on reddit claims to have downloaded a mouse configuration tool from their official website. Upon noticing suspicious activity, they investigated further and discovered that the software contained a hidden trojan identified as 'Synaptics.exe'. This incident was not isolated; another user reported finding similar malware embedded within the software for another gaming mouse utility tool. Talk about a mouse becoming a RAT
Pranav Kalidas
Aug 43 min read
Â
Â


A reality check for SOC teams relying blindly on geographic log parameters
Predictable Local Activity May Reduce Analyst Vigilance For SOC analysts who spend their days triaging Microsoft 365 login events, the daily routine often falls into a predictable pattern. Security teams often implement a binary triage logic: local logins are automatically marked as benign, while foreign logins undergo a deeper analysis verification. This creates a dangerous security gap. Logins from local IP: Check the sign-in IP -> If itâs a local IP -> Close as expected/be
Emanuel Falzon
Jun 243 min read
Â
Â


How to Think Like an Investigator Instead of an Alert Reviewer
Security incidents are solved through context and correlation - not alert queues. Most SOC environments are optimized for speed. Analysts are measured by ticket closures, SLA adherence, and alert throughput. On paper, that sounds efficient. In practice, it creates a dangerous habit: reviewing alerts instead of investigating incidents. An alert is not an investigation. It is a signal that something may require attention. Yet many security teams treat alerts as isolated tasks i
Andy Urlep
May 254 min read
Â
Â


From Alerts to Hours: The Hidden Cost of Noise
Over 1 Million Alerts â Whatâs Behind That Number? Over the last 7 days, this environment generated 1,107,211 alerts. At first glance, that sounds like strong security coverage. But hereâs the reality: More alerts donât mean more protection â they often mean more noise. The real question is not how many alerts were generated, but: How many of these actually matter? Use Case: SMB to Public IP To understand how this pattern behaves across the environment, we zoomed into a speci
Andy Urlep
Apr 293 min read
Â
Â


Threat actors don't need your password or MFA to compromise your users
Cybersift is observing a modern type of phishing attacks on Office 365 users which deviate from the typical fake login web page, we analysts are typically accustomed to seeing. The new phishing attack utilizes device registration to compromise the victimâs account, meaning that the threat actor does not require to steal your password to gain entry. But this modern phishing attack is smarter than you might think. Case Study We analyzed a phishing email which utilized a device
Emanuel Falzon
Apr 283 min read
Â
Â


Deconstructing the Tor Exit Node Attack on Microsoft
Introduction As the digital backbone for millions of enterprises, Microsoft Office 365 has become the primary option for modern identity-based warfare. Todayâs attackers don't just "log in" they meticulously craft digital fingerprints to mirror legitimate employees, attempting to slip past automated defense unnoticed. This analysis explores a high-severity incident where a corporate account was compromised through a combination of network anonymization and device metadata man
Nootan Ranga Nayak
Apr 282 min read
Â
Â


How to Optimise Incident Response and Streamline SOC Operations
Security Operations Centers (SOCs) are under severe pressure to defend organisations due to evolving cyber threats. However, many SOC teams struggle with alert fatigue, slow response times, and fragmented security tools that makes it challenging to manage incidents effectively. Traditional manual incident response processes are inefficient. They require analysts to examine massive amounts of security alerts, correlate data from multiple sources, and respond to threats manuall
CyberSift
Feb 28, 20254 min read
Â
Â
bottom of page
