DEGOOLCYBER SECURITY SOLUTIONS
INSIGHTS

Research & advisories

Detection engineering notes, adversary teardowns and regional advisories from the DeGooL research team.

ADVISORY04 SEP 2026

CVE-2026-1188: pre-auth RCE in edge VPN appliances

Exploitation observed in the wild against GCC targets within 36 hours of disclosure. Detection logic and compensating controls below.

RESEARCH TEAM · 6 MIN READ

DETECTION28 AUG 2026

Writing detections that survive contact with production

Why most rules die in tuning, and how detection-as-code with pre-merge replay against historical telemetry fixes it.

DETECTION ENGINEERING · 11 MIN READ

TEARDOWN19 AUG 2026

SANDSTORM LEDGER: anatomy of a regional banking campaign

Full TTP breakdown of a financially motivated cluster targeting GCC retail banking, with IOCs and hunting queries.

THREAT INTELLIGENCE · 14 MIN READ

AI SECURITY07 AUG 2026

What we log when an LLM makes a security decision

Auditability of model-assisted triage: what a reasoning trace must contain to be defensible to an auditor.

PLATFORM · 9 MIN READ

OT / ICS22 JUL 2026

Passive monitoring in safety-critical environments

How to get asset inventory and anomaly detection in a Purdue Level 1 network without ever sending a packet.

OT PRACTICE · 8 MIN READ

COMPLIANCE11 JUL 2026

ISO 27001 in eleven weeks: what actually determines the timeline

It is never the controls. It is evidence collection, ownership ambiguity and audit scheduling — in that order.

GOVERNANCE · 7 MIN READ

Article bodies are not yet written — these cards link nowhere until the client supplies the copy.

Find out what your telemetry is already telling you.

Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.