Ransomware KQL Windows

STORM-1175: KQL Detections for Medusa Ransomware Operations

April 6, 2026 12 min read

Storm-1175 is a financially motivated actor operating high-velocity Medusa ransomware campaigns, weaponising N-day vulnerabilities within days of disclosure. The group has targeted healthcare, education, finance, and professional services across Australia, the UK, and the US, moving from initial exploitation to full ransomware deployment in under 24 hours. This post covers 8 KQL detections across the full attack chain.

Read more →
APT KQL VMware

BRICKSTORM: KQL Detections for vSphere Backdoor Activity

April 5, 2026 10 min read

BRICKSTORM is a Go-based backdoor attributed to UNC5221 / Warp Panda targeting VMware vSphere infrastructure. Operating beneath the guest OS layer, it exploits the EDR visibility gap on virtualisation control planes. This post covers 8 KQL detections spanning initial access through to C2 and tamper detection.

Read more →

Hello World

March 28, 2026 1 min read

This is a small cyber threat intelligence blog where I write about anything I find interesting, or that could be helpful.

Read more →