Detecting Suspicious RMM Tool Execution Chains in Microsoft Defender (T1219)

One of the most common initial access vectors into environments by threat actors is through use of legitimate RMM tooling, offering both hands-on-keyboard access as well as stealth. Read more below for some considerations on detecting such activity.

July 10, 2026 · 9 min · Matt Swann

Detection Deep Dive: Encoded PowerShell Commands (T1059.001)

The first entry in the Detection Deep Dive series: mapping encoded PowerShell execution to detection logic in Microsoft Defender, tuning out the false positives, and knowing what the detection can’t see.

July 7, 2026 · 4 min · Matt Swann

Advent of Cyber 2025 Day 21 — Malware Analysis Bonus Challenge

A walkthrough of the TryHackMe Advent of Cyber 2025 Day 21 bonus challenge: peeling back a multi-layer HTA payload through VBScript analysis, Base64 decoding, and XOR decryption to uncover a hidden PNG.

December 21, 2025 · 5 min · Matt Swann