
CVE-2026-1188: pre-auth RCE in edge VPN appliances
Exploitation observed in the wild against GCC targets within 36 hours of disclosure. Detection logic and compensating controls below.
RESEARCH TEAM · 6 MIN READ
Detection engineering notes, adversary teardowns and regional advisories from the DeGooL research team.

Exploitation observed in the wild against GCC targets within 36 hours of disclosure. Detection logic and compensating controls below.
RESEARCH TEAM · 6 MIN READ

Why most rules die in tuning, and how detection-as-code with pre-merge replay against historical telemetry fixes it.
DETECTION ENGINEERING · 11 MIN READ

Full TTP breakdown of a financially motivated cluster targeting GCC retail banking, with IOCs and hunting queries.
THREAT INTELLIGENCE · 14 MIN READ

Auditability of model-assisted triage: what a reasoning trace must contain to be defensible to an auditor.
PLATFORM · 9 MIN READ

How to get asset inventory and anomaly detection in a Purdue Level 1 network without ever sending a packet.
OT PRACTICE · 8 MIN READ

It is never the controls. It is evidence collection, ownership ambiguity and audit scheduling — in that order.
GOVERNANCE · 7 MIN READ
Article bodies are not yet written — these cards link nowhere until the client supplies the copy.
Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.