Blog
The dogesec blog
-
Turn any Blog Post into Structured Threat Intelligence
PRODUCTS November 11, 2024
Obstracts is the blog feed reader used by the worlds most targetted cyber-security teams. Let me show you why. -
An Analysis of the Changes in ATT&CK Version 16.0
RESEARCH November 04, 2024
Your handy guide to streamlining upgrades of MITRE ATT&CK by comparing the changes made between releases. -
Bad Software Keeps Cyber Security Companies in Business
RESEARCH October 28, 2024
Despite countless frameworks, best practices, blog posts... so many developers still hardcode credentials into their code. -
When the Wayback Machine Went Down, so did our Software
PRODUCTS October 14, 2024
A short lesson in why building a product with a single point of failure is bad (duh!), and our hunt for a Wayback Machine alternative. -
17,375 CVEs in the NVD Backlog, and Counting
RESEARCH October 07, 2024
The NVD are still struggling to keep up with the backlog of CVEs to be analysed. With 26,876 added since February, it is no surprise. -
Analysing 25 Years of CVEs
RESEARCH September 30, 2024
The CVE List was launched in September 1999, listing 321 CVE records. 25 years later there are 265,767 CVE records. -
A Deeper Look at a TAXII Client
PRODUCTS September 16, 2024
We built an open-source TAXII server, Arango TAXII Server. Here are some examples of how you can consume data from it using a TAXII Client. -
Using STIX Objects to Make Vulnerability Prioritisation Easy (and Free)
TUTORIAL September 02, 2024
Follow along as I show you how to store 200,000 CVEs as STIX objects, then use CVSS, EPSS, CISA KEV and CPE data to search and filter them. -
A Producers Guide to Sharing Cyber Threat Intelligence
PRODUCTS August 26, 2024
txt2stix + stix2arango + arango_taxii_server = a robust and flexible setup for storing and distributing cyber threat intelligence you've produced. -
A MITRE ATT&CK Style Knowledge Base for Ransomware
PRODUCTS August 19, 2024
After becoming ever-more frustrated by intelligence producers naming the same ransomware slightly differently, and with ATT&CK missing lots of ransomware types, I finally got around to trying to solve the problem.