Notes from the investigation layer.
Blog
On evidence, verdicts, and running a SOC with automation you can audit.
- 21 September 2026
8 min read
Oryen teamThe most common MITRE ATT&CK techniques in the SOC
Red Canary's 2026 Threat Detection Report ranks the techniques behind confirmed threats, and ten of them account for 46 percent of all detections. We wrote a proof contract for each of the top ten and found that six recurring predicates carry most of the work — and that one missing log makes the fourth-ranked technique impossible to close.
Read - 8 September 2026
6 min read
Oryen teamYour AI agent can close an alert. Should it be allowed to?
Giving an agent access to security tools is increasingly straightforward. Giving a SOC confidence that the agent has completed an investigation is a different problem — and a plausible explanation is not the same as a completed investigation.
Read