Steven Stone
Cyber threat intelligence analyst, threat hunter, and detection engineer. This site holds my intelligence reports, hunt guides, and detection rules, and the tools I build to produce them.
- 194
- Reports
- 59
- Hunt guides
- 20
- Weekly summaries
- 17
- Actors covered
Latest reports
All reports →- 2026-10-08Intel ReportHunt GuideOracle Health Cerner Breach Confirmed at Nearly 20 Million Affected Individuals Following Texas AG Disclosure
- 2026-10-08Intel ReportCybercrimeSenate Passes Health Care Cybersecurity and Resiliency Act After Change Healthcare Exposed 190 Million Records
- 2026-10-06Intel ReportHunt GuideCitrix NetScaler ADC and Gateway Three Zero-Days Exploited With WHIPSHOT and SLAPSHOT Malware Across Government and Financial Sectors
- 2026-10-01Intel ReportHunt GuideCisco SD-WAN and Firewall Product Lines Accumulate 12 Exploited CVEs as UAT-8616 Campaign Expands
- 2026-10-01Intel ReportHunt GuideCybercrimeH1 2026 Healthcare Data Breach Report: 281 Compromises, 2.3 Daily Ransomware Attacks, and a 24% Attack-Vector Disclosure Rate
- 2026-10-01Intel ReportCybercrimeFlashpoint Awarded Patent for Ransomware Risk Model That Scores Vulnerabilities at Disclosure
- 2026-09-30Intel ReportHunt GuideCybercrimeHealthcare Breach Data Through Mid-2026: Declining Breach Counts, Sustained Ransomware Volume, and Expanding Insider Threat
- 2026-09-30Intel ReportHunt GuideCybercrimeShinyHunters Identity Extortion, Oracle PeopleSoft Mass Exploitation, and Supply Chain Breaches Converge on the Healthcare Sector
Projects
All projects →TrendPulse
OperationalThe collection and production pipeline behind the reports on this site: source collection, scoring, drafting, and a verification gate that checks every indicator, CVE, and citation against the fetched source text before anything is published.
CTI Threat Hunt Map
LiveAn ATT&CK v19.1 hunt reference: 375 hunts and 225 LOLBins with copy-ready Splunk, Elastic, and Corelight queries, cross-linked to 212 threat actors. Runs entirely in the browser.
Windows Event Log Field Manual
LiveAdvanced Windows Event Log Analysis (AWELA): 77 sections covering triage playbooks, process and system baselines, attack detection, and event references for Security, System, PowerShell, and Sysmon logs. Every query in Splunk SPL.
Honeypot Sensor Network
OperationalA T-Pot deployment running 30+ honeypot services on cloud infrastructure since March 2026. It collects attack telemetry and payloads for analysis and future malware reports.