Threat intelligence // Defensive operations
Turn threat evidence into actions your team can defend.
Vetted SecOps connects current campaigns, time-bound IOC evidence and practitioner review to the decisions SOC, threat intelligence and detection teams make every day.
- Source and freshness preserved
- Human approval before publication
- Operational limits made explicit
Operational products
Built for the decision between a feed match and an action.
Each tool preserves the evidence boundary: what is known, how fresh it is, what still needs local context, and where a human decision begins.
Threat Action Pack
Move from current public intelligence to a reviewed package of indicators, source context, freshness and recommended analyst handling.
- Current campaign context
- Time-bound IOC evidence
- Human approval gate
IOC Decision Lookup
Query an IP, domain, URL or hash without pretending that a match is automatically a block decision.
- Automatic IOC type detection
- Source and expiry visible
- Operational interpretation
Vulnerability Decision Brief
Apply official CISA SSVC while keeping KEV, EPSS and CVSS separate, then export an evidence-ready handoff.
- Official SSVC outcome
- Live KEV and EPSS context
- Client-side assessment
Practitioner-led
Built from the operating side of security.
Vetted SecOps is independently edited by a cybersecurity specialist with experience managing a Managed Detection and Response service and working across enterprise defensive technologies.
Automation prepares evidence. It does not approve an article, invent a conclusion or publish without human review.
Experience, credentials and editorial responsibility- 01
- Primary sources first
- 02
- Evidence gaps disclosed
- 03
- Corrections recorded
Selected research
Campaigns, tradecraft and defensive opportunities.
Mitigating Storm-2945 CaptiveCrunch attacks on traveling workforce
Captive-portal abuse, Entra ID credential theft and host artifacts translated into immediate controls and hunt actions.
XCSSET v40 targets developers through poisoned Xcode projects
Fileless persistence, update impairment and Chrome DevTools abuse with an implementation-focused checklist.
Defending against AI token jacking and transfer-station abuse
How stolen API credentials become a billing and data-exposure problem, plus the controls that reduce reuse.
Evidence pipeline
Useful because the limits travel with the finding.
The publication and products use the same operating discipline.
- 01
Collect
Start with official advisories, primary research and redistribution-reviewed intelligence.
- 02
Preserve
Keep source, license, first seen, last seen, confidence and missing context attached.
- 03
Decide
Translate evidence into a defensible action without hiding the analyst judgement.
Latest operational briefs
- How to Make Vulnerability Decisions Defensible with SSVC, KEV, and EPSSA practical operating guide to preserving CVSS, EPSS, and KEV as distinct signals, applying CISA SSVC, and producing an evidence-ready vulnerability decision.
- CVE-2025-66376: Detect and Contain LAUNDRY BEAR in ZimbraCISA and international partners warn of Russian state-sponsored APT LAUNDRY BEAR actively exploiting CVE-2025-66376 in Zimbra Collaboration Suite to exfiltrate email data, Global Address Lists, and credentials.
- Beyond the Hype: Practical AI/ML Evasion Techniques in Modern EDRsBeyond the Hype: Practical AI/ML Evasion Techniques in Modern EDRs Endpoint Detection and Response (EDR) platforms have fundamentally shifted security operations from reactive signature-based … Read more
Adoption kit // Early access
Take defensible decisions into the workflow your team already uses.
Join the focused release list for the Vulnerability Decision Adoption Kit and material Vetted SecOps product updates. No generic daily digest.
Explicit opt-in. Unsubscribe at any time.