the dogesec blog
Tutorials, research, and product updates on STIX, ATT&CK, Sigma, cyber threat intelligence engineering, and threat intel automation.
-
A Proposal for Sigma Investigation Guides for Agents
Tutorials July 20, 2026
A proposal for a portable Sigma Investigation Guide format that helps security agents and analysts investigate alerts consistently, auditably, and across platforms. -
What is PAP, and Why Does it Matter in Cyber Threat Intelligence?
Tutorials June 15, 2026
PAP explains what recipients are allowed to do with intelligence, not just who they can share it with. This post covers why that distinction matters and how OASIS models PAP in STIX 2.1. -
Why Vulmatch Models CWEs as STIX Weakness Objects
Tutorials May 17, 2026
Vulmatch models CVEs and CWEs as first-class STIX objects. This post explains why coupling a CVE to a CWE reference is not enough, how cwe2stix defines a Weakness SDO, and what that unlocks in practice. -
Representing Admiralty Codes in STIX Without Giving Up Interoperability
Tutorials April 13, 2026
A practical approach to modelling Admiralty Codes in STIX 2.1 using Marking Definitions and Extension Definitions, with reusable objects you can adopt in your own CTI workflows. -
Introducing the Cyber Threat Exchange: A Better Way to Publish and Consume CTI Feeds
Updates March 16, 2026
Learn how the Cyber Threat Exchange helps researchers publish structured CTI in STIX 2.1 and lets defenders operationalise specialist intelligence through TAXII, APIs, and existing CTI tooling. -
TTPs Are Missing the P: Lets Fix That
Research February 23, 2026
Most ATT&CK programs model tactics and techniques, but not procedures. This post explains why that gap matters, where Attack Flow helps, and how STIX could model the missing layer. -
Using Known ATT&CK Techniques to Predict What Came Before and What Happens Next
Research February 16, 2026
Known ATT&CK techniques are not just for labeling incidents. This post shows how to use them as anchors to infer likely predecessor and successor behavior in a realistic adversary sequence, and how MITRE TIE can support that workflow. -
Detection Isn’t Defence: Linking ATT&CK to D3FEND
Research February 09, 2026
D3FEND becomes far more useful when it is not isolated. This post shows how D3FEND links to ATT&CK and CWE through artefacts, so you can traverse from offensive technique or weakness to concrete defensive mitigations. -
Stop Wasting Agent Tokens on ATT&CK Lookups
Updates February 02, 2026
Most AI CTI workflows waste tokens rediscovering ATT&CK, CWE, CAPEC, and other CTI knowledgebases from scratch. CTI Butler fixes that by giving agents a structured retrieval layer. In this post I show how to turn it into a Claude Code skill that recommends likely mappings from raw analyst input. -
Stop Reinventing STIX Objects: A Practical Way to Build and Share Extensions
Tutorials January 19, 2026
Learn how to avoid ad-hoc custom objects by generating schemas and Extension Definitions automatically with stix2extensions, keeping STIX extensions interoperable by default.
No posts matched your search.