詳細検索

SOC運用


How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?
Security
February 23, 2026
2分で読めます

How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?

Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security

OSINT and SQL Injection Threats|What are the Risks of Exposing Admin Pages?
Security
January 23, 2026
6分で読めます

OSINT and SQL Injection Threats|What are the Risks of Exposing Admin Pages?

OSINT Explains Admin Page Identification and SQL Injection Attack Flow, WAF Evasion Methods, Detection Methods, and Defense-in-Depth Practices|Colorkrew Security

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points
Security
January 22, 2026
4分で読めます

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

How to choose a SIEM that won't fail|How to compare the purpose × operation design
Security
January 21, 2026
4分で読めます

How to choose a SIEM that won't fail|How to compare the purpose × operation design

Explains the purpose, scenario design, system building, and specific methods of ransomware attack exercises led by CSIRT. Practical Security Training to Enhance Detection and Response|Colorkrew Security

Active Directory Defense Essentials|Defender for Identity Explained
Security
January 19, 2026
4分で読めます

Active Directory Defense Essentials|Defender for Identity Explained

Explaining how Defender for Identity detects lateral deployment and privilege escalation attacks targeting Active Directory, how it differs from EDR and SIEM, and how it can be used in SOC operations|Colorkrew Security

Will AI evolve malware? Gemini exploitative attacks PROMPTFLUX and PROMPTSTEAL
Security
December 26, 2025
4分で読めます

Will AI evolve malware? Gemini exploitative attacks PROMPTFLUX and PROMPTSTEAL

Explains the threat of new malware PROMPTFLUX and PROMPTSTEAL, which exploit generative AI such as Gemini to autonomously mutate and generate instructions. Organize attack methods and practical countermeasures based on GTIG reports|Colorkrew Security

Cyber Threat Intelligence (CTI) Deployment Guide | Modern Defense Strategies to Anticipate Attacks
Security
December 23, 2025
3分で読めます

Cyber Threat Intelligence (CTI) Deployment Guide | Modern Defense Strategies to Anticipate Attacks

We will explain the basics of cyber threat intelligence (CTI), implementation procedures, and how to use it in SOC and SIEM. A practical guide to anticipating attacks and reducing risk for your organization. |Colorkrew Security

[January 2026 Edition] Summary of vulnerabilities to be addressed now|React, n8n, MongoDB
Security
December 21, 2025
4分で読めます

[January 2026 Edition] Summary of vulnerabilities to be addressed now|React, n8n, MongoDB

Explain the vulnerabilities that should be addressed as a priority in January 2026. Based on CVE information related to React, n8n, and MongoDB, we organize the scope of impact and specific countermeasure points, and use them to determine priorities in SOC operations|Colorkrew Security

What is NIST CSF 2.0? Deployment guide to increase enterprise security maturity
Security
December 21, 2025
3分で読めます

What is NIST CSF 2.0? Deployment guide to increase enterprise security maturity

This section covers an overview of NIST CSF 2.0, implementation procedures, and practical points to enhance security maturity. A Guide for Enterprises Considering Strengthening Governance and SOC Alignment|Colorkrew Security

What should Zero Trust do after all? Explanation of practical steps to start in the field
Security
December 19, 2025
3分で読めます

What should Zero Trust do after all? Explanation of practical steps to start in the field

What does Zero Trust do? From the essence of the concept to MFA, device management, and data protection, we will explain the practical points that can be started in the field|Colorkrew Security

[Can be used in the field] MITRE ATT&CK Utilization Guide! Strengthen your defenses by gaining visibility into attacker modus operandi
Security
December 8, 2025
3分で読めます

[Can be used in the field] MITRE ATT&CK Utilization Guide! Strengthen your defenses by gaining visibility into attacker modus operandi

It explains in an easy-to-understand manner from the basics of MITRE ATT&CK to its structure, how to view the matrix, and how to use it in the field. This is a practical guide to help you analyze gaps and strengthen countermeasures|Colorkrew Security

Will AI replace SOC? What is the realistic future for corporate security operations?
Security
December 7, 2025
3分で読めます

Will AI replace SOC? What is the realistic future for corporate security operations?

Will AI replace SOC? In this article, we will sort out the areas of AI's strengths and weaknesses, explain the differences from the judgment work that SOCs are responsible for, and the areas that can be strengthened by using AI|Colorkrew Security