<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Annoyed Engineer</title><description>Engineering is annoying.</description><link>https://annoyed.engineer/</link><item><title>Phishing as a Service 2.0: The Franchise Model of Cybercrime</title><link>https://annoyed.engineer/2025/08/30/phishing-as-a-service-2-0-the-franchise-model-of-cybercrime/</link><guid isPermaLink="true">https://annoyed.engineer/2025/08/30/phishing-as-a-service-2-0-the-franchise-model-of-cybercrime/</guid><description>The Golden Arches of Malice When you think of franchising, you probably picture McDonald’s, Starbucks, or Subway — not cybercriminals. But the uncomfortable truth is that modern cybercrime looks a lot less like “lone hacker in a hoodie” and a lot more like fast food chains. Instead of flipping burgers, they’re flipping login pages. Instead…</description><pubDate>Sat, 30 Aug 2025 19:04:27 GMT</pubDate></item><item><title>LLMs in Security Operations: Helpful Sidekick or Hallucinating Intern?</title><link>https://annoyed.engineer/2025/07/20/llms-in-security-operations-helpful-sidekick-or-hallucinating-intern/</link><guid isPermaLink="true">https://annoyed.engineer/2025/07/20/llms-in-security-operations-helpful-sidekick-or-hallucinating-intern/</guid><description>Large language models (LLMs) are everywhere now. Your inbox, your SIEM, maybe even embedded in your security tool’s new “AI assistant” tab. It’s tempting to believe these tools are ready to triage alerts, write detections, and handle analyst fatigue all on their own. They aren’t. Not yet. But that doesn’t mean they’re useless. Like any…</description><pubDate>Mon, 21 Jul 2025 01:06:36 GMT</pubDate></item><item><title>Trust Engineering: Building Security People Actually Believe In</title><link>https://annoyed.engineer/2025/07/20/trust-engineering-building-security-people-actually-believe-in/</link><guid isPermaLink="true">https://annoyed.engineer/2025/07/20/trust-engineering-building-security-people-actually-believe-in/</guid><description>Security doesn’t work without trust. You can deploy all the right tools, write high-fidelity detections, and put together a solid incident response plan—but if the engineers roll their eyes every time you file a ticket, or leadership treats your risk assessments like noise, the entire program grinds down. This post is about something security teams…</description><pubDate>Mon, 21 Jul 2025 01:06:02 GMT</pubDate></item><item><title>The Detection Rebuild, Part 2: Automating Detection Engineering Without Breaking the SOC</title><link>https://annoyed.engineer/2025/07/14/the-detection-rebuild-part-2-automating-detection-engineering-without-breaking-the-soc/</link><guid isPermaLink="true">https://annoyed.engineer/2025/07/14/the-detection-rebuild-part-2-automating-detection-engineering-without-breaking-the-soc/</guid><description>Coming off the heels of Part 1, where we focused on fixing the signal problem, Part 2 is all about scale. Because once you’ve cleaned up your alerts and improved your detection quality, the next question is: how do you keep it that way without burning your team out? This post is a practical look…</description><pubDate>Tue, 15 Jul 2025 03:53:07 GMT</pubDate></item><item><title>The Detection Rebuild, Part 1: Fixing the Signal Problem</title><link>https://annoyed.engineer/2025/07/14/the-detection-rebuild-part-1-fixing-the-signal-problem/</link><guid isPermaLink="true">https://annoyed.engineer/2025/07/14/the-detection-rebuild-part-1-fixing-the-signal-problem/</guid><description>How to Stop Drowning in False Positives and Start Surfacing Real Threats Let’s be honest: most security teams aren’t short on alerts—they’re short on good ones. Every SOC eventually hits the same wall: too many alerts, not enough signal, and a growing pile of detection rules no one wants to touch because something might break.…</description><pubDate>Tue, 15 Jul 2025 03:33:04 GMT</pubDate></item><item><title>Tycoon 2FA: How Storm-1747 Built an MFA-Bypassing Phishing Empire</title><link>https://annoyed.engineer/2025/06/04/tycoon-2fa-how-storm-1747-built-an-mfa-bypassing-phishing-empire/</link><guid isPermaLink="true">https://annoyed.engineer/2025/06/04/tycoon-2fa-how-storm-1747-built-an-mfa-bypassing-phishing-empire/</guid><description>We used to believe MFA was the ultimate line of defense. Then phishing kits like Tycoon 2FA showed up and proved otherwise. Unlike the crude clones of years past, Tycoon 2FA leverages Adversary-in-the-Middle (AiTM) tactics to seamlessly intercept credentials and MFA tokens in real time. It looks polished, behaves like the real thing, and operates…</description><pubDate>Thu, 05 Jun 2025 03:41:45 GMT</pubDate></item><item><title>The Real Threat in the Middle: How Mid-Stage Adversaries Are Outsmarting MFA and Scaling Fast</title><link>https://annoyed.engineer/2025/06/01/the-real-threat-in-the-middle-how-mid-stage-adversaries-are-outsmarting-mfa-and-scaling-fast/</link><guid isPermaLink="true">https://annoyed.engineer/2025/06/01/the-real-threat-in-the-middle-how-mid-stage-adversaries-are-outsmarting-mfa-and-scaling-fast/</guid><description>For years, multi-factor authentication (MFA) has been the security world’s favorite answer to “what should we do about phishing?” But attackers don’t wait for the controls to get better—they evolve around them. Enter the mid-stage adversary: a new class of attacker that’s rapidly scaling intrusions with help from phishing-as-a-service (PhaaS) platforms and adversary-in-the-middle (AiTM) toolkits.…</description><pubDate>Sun, 01 Jun 2025 19:51:16 GMT</pubDate></item><item><title>Security Debt Is Worse Than Tech Debt — and Twice as Invisible</title><link>https://annoyed.engineer/2025/05/21/security-debt-is-worse-than-tech-debt-and-twice-as-invisible/</link><guid isPermaLink="true">https://annoyed.engineer/2025/05/21/security-debt-is-worse-than-tech-debt-and-twice-as-invisible/</guid><description>Security Debt Is Worse Than Tech Debt — and Twice as Invisible We talk about tech debt like it’s a necessary evil. Move fast, break things, fix it later. Everyone’s cool with that. But security debt? That’s the quiet killer. It creeps in unnoticed, hides in your TODOs, and doesn’t scream until you’ve got ransomware…</description><pubDate>Thu, 22 May 2025 03:08:01 GMT</pubDate></item><item><title>Why AI is Just Another Tool in Our Blue Team Toolbox</title><link>https://annoyed.engineer/2025/04/17/why-ai-is-just-another-tool-in-our-blue-team-toolbox/</link><guid isPermaLink="true">https://annoyed.engineer/2025/04/17/why-ai-is-just-another-tool-in-our-blue-team-toolbox/</guid><description>You can’t scroll through LinkedIn, attend a security conference, or open a vendor whitepaper these days without hearing that AI is about to replace the SOC. Some companies claim AI can triage alerts, write detections, respond to incidents, and make coffee while you’re still getting through your inbox. Let me be blunt: That’s not happening.…</description><pubDate>Fri, 18 Apr 2025 02:33:03 GMT</pubDate></item><item><title>How I Got ChatGPT to Write Ransomware (and Why That Actually Matters)</title><link>https://annoyed.engineer/2025/04/14/how-i-got-chatgpt-to-write-ransomware-and-why-that-actually-matters/</link><guid isPermaLink="true">https://annoyed.engineer/2025/04/14/how-i-got-chatgpt-to-write-ransomware-and-why-that-actually-matters/</guid><description>Introduction: The AI Cybersecurity Paradox If you’ve ever tried to ask ChatGPT to help you build ransomware, chances are you got shut down fast. Like, brick-wall fast. That’s because AI models like ChatGPT are built with strong ethical guardrails that are designed to prevent the creation of malware, exploits, and anything remotely shady. And that’s…</description><pubDate>Tue, 15 Apr 2025 02:34:36 GMT</pubDate></item><item><title>Detection Engineering 101: Using AI to Write One Rule and Convert It Everywhere</title><link>https://annoyed.engineer/2025/03/13/detection-engineering-101-using-ai-to-write-one-rule-and-convert-it-everywhere/</link><guid isPermaLink="true">https://annoyed.engineer/2025/03/13/detection-engineering-101-using-ai-to-write-one-rule-and-convert-it-everywhere/</guid><description>Detection engineering is a beautiful, frustrating, and often tedious art. You write a killer detection for one SIEM, pat yourself on the back, and then—bam—your SOC lead tells you it also needs to work in Splunk. And Sentinel. And whatever other logging monstrosity they’re using this week. Now, you have two choices: 1. Spend your…</description><pubDate>Fri, 14 Mar 2025 02:37:05 GMT</pubDate></item><item><title>Why SOC Automation Usually Fails: Lessons from the Field</title><link>https://annoyed.engineer/2025/03/13/why-soc-automation-usually-fails-lessons-from-the-field/</link><guid isPermaLink="true">https://annoyed.engineer/2025/03/13/why-soc-automation-usually-fails-lessons-from-the-field/</guid><description>Security Operations Centers (SOCs) are always under pressure—too many alerts, not enough analysts, and an ever-growing attack surface. Enter automation, the supposed magic bullet to eliminate manual work, reduce response times, and make security teams more efficient. Except… it rarely works as advertised. Despite the promises of AI-driven SOAR (Security Orchestration, Automation, and Response) and…</description><pubDate>Fri, 14 Mar 2025 02:34:53 GMT</pubDate></item><item><title>The Trojan Sysadmin: How I Got an AI to Build a Wolf in Sheep’s Clothing</title><link>https://annoyed.engineer/2025/02/22/the-trojan-sysadmin-how-i-got-an-ai-to-build-a-wolf-in-sheeps-clothing/</link><guid isPermaLink="true">https://annoyed.engineer/2025/02/22/the-trojan-sysadmin-how-i-got-an-ai-to-build-a-wolf-in-sheeps-clothing/</guid><description>There’s been endless debate about whether AI can churn out malicious code—or if it’s too principled to cross that line. So, I took Grok 3 for a spin to find out. My goal? Trick it into writing what’s basically ransomware. Spoiler: it was a cakewalk. Objective The experiment explored whether an AI language model (Grok…</description><pubDate>Sun, 23 Feb 2025 02:57:52 GMT</pubDate></item><item><title>The Practitioner’s  Guide to Kubernetes Security</title><link>https://annoyed.engineer/2025/01/19/the-practitioners-guide-to-kubernetes-security/</link><guid isPermaLink="true">https://annoyed.engineer/2025/01/19/the-practitioners-guide-to-kubernetes-security/</guid><description>Kubernetes has change the way we deploy and manage containerized applications, enabling scalability and automation in ways we never imagined. However, with great power comes great responsibility. Which means a whole lot more complexity and security challenges. From misconfigured RBAC to exposed APIs, Kubernetes clusters are a prime target for attackers. Securing a Kubernetes environment…</description><pubDate>Mon, 20 Jan 2025 04:03:27 GMT</pubDate></item><item><title>Securing Data in a Privacy-First World: Challenges and Solutions</title><link>https://annoyed.engineer/2025/01/16/securing-data-in-a-privacy-first-world-challenges-and-solutions/</link><guid isPermaLink="true">https://annoyed.engineer/2025/01/16/securing-data-in-a-privacy-first-world-challenges-and-solutions/</guid><description>I’ve decided to change it up a bit and switch to a conversation on protecting sensitive data in your cloud environments. But, it still has a SecOps feel! I’m focusing on AWS in this post, but this should be applied anywhere, no matter the cloud host. This technical guide dives into how organizations can secure…</description><pubDate>Fri, 17 Jan 2025 02:17:58 GMT</pubDate></item><item><title>The Art and Science of Threat Detection: SIEM and Detection Engineering Essentials</title><link>https://annoyed.engineer/2024/11/12/the-art-and-science-of-threat-detection-siem-and-detection-engineering-essentials/</link><guid isPermaLink="true">https://annoyed.engineer/2024/11/12/the-art-and-science-of-threat-detection-siem-and-detection-engineering-essentials/</guid><description>I’ve decided to tie this post and one other on Building an Effective Security Operations Program together instead of posting them weeks apart. I wanted to focus on the high level aspect of building out a proper security operations focused on Detection and Response, but I also felt like we needed to really dig into…</description><pubDate>Wed, 13 Nov 2024 03:20:20 GMT</pubDate></item><item><title>Building an Effective Security Operations Program: Focusing on Detection and Response</title><link>https://annoyed.engineer/2024/11/12/building-an-effective-security-operations-program-focusing-on-detection-and-response/</link><guid isPermaLink="true">https://annoyed.engineer/2024/11/12/building-an-effective-security-operations-program-focusing-on-detection-and-response/</guid><description>Hey everyone! We’re going to be focusing on building out the core competent of your SOC! This post is going to be pretty high level, not too in the weeds as I want to cover the hot items that go into the average SOC these days. There is a more technical blog along side this…</description><pubDate>Wed, 13 Nov 2024 03:18:46 GMT</pubDate></item><item><title>From Detection to Prevention: Crafting a Proactive Threat Detection Strategy</title><link>https://annoyed.engineer/2024/11/07/threat-detection-strategy/</link><guid isPermaLink="true">https://annoyed.engineer/2024/11/07/threat-detection-strategy/</guid><description>Recently, I’ve been thinking more and more about our Threat Detection processes and what we’ve been doing to increase our detection capabilities. Because of that, I thought I would try and articulate at a high level a relatively normal Threat Detection Strategy that focuses on Detection &amp; Prevention. I’ll be doing a series of posts…</description><pubDate>Fri, 08 Nov 2024 04:46:26 GMT</pubDate></item><item><title>The Brutus Botnet</title><link>https://annoyed.engineer/2024/03/23/the-brutus-botnet/</link><guid isPermaLink="true">https://annoyed.engineer/2024/03/23/the-brutus-botnet/</guid><description>UPDATE 03/14/25 Since publishing our research on what we suspected to be a botnet—Brutus—back in 2024, new findings have surfaced that confirm some of our theories while also filling in the gaps we couldn’t quite close. A recent report from EclecticIQ (link) finally ties Brutus to the Black Basta ransomware operation. Turns out, what we…</description><pubDate>Sat, 23 Mar 2024 17:33:30 GMT</pubDate></item><item><title>Getting burned in the Cloud</title><link>https://annoyed.engineer/2023/12/31/getting-burned-in-the-cloud/</link><guid isPermaLink="true">https://annoyed.engineer/2023/12/31/getting-burned-in-the-cloud/</guid><description>It has finally happened to me… I’ve finally made a “mistake” in Azure that costed me money… In my defense the default setting changed, and I didn’t notice it. The goal was to setup some backups in Azure with their cold storage. Pretty simple right? It’s super straightforward and I was up in running in…</description><pubDate>Mon, 01 Jan 2024 03:45:44 GMT</pubDate></item><item><title>Annoying Azure Bug</title><link>https://annoyed.engineer/2023/12/31/annoying-azure-bug/</link><guid isPermaLink="true">https://annoyed.engineer/2023/12/31/annoying-azure-bug/</guid><description>Boy oh boy, did Azure piss me off this time. I’ll start by saying I tend to enjoy working in Azure over the other major cloud providers out there. But it’s fair to say, Azure has PLENTY of quirks. A while back, I was working with a client on a consulting gig I’m doing on…</description><pubDate>Mon, 01 Jan 2024 03:45:28 GMT</pubDate></item></channel></rss>