Binary Defense
Corporate/Government Newsroom
With 86,400 seconds in a day, you need a trusted security partner to shield you for every single one. At Binary Defense, that’s the promise we make to our clients. We know that the best cybersecurity protection for your business takes a team of real people detecting real threats in real time. Source
Actions
Media Outlet details
| Scope | Consumer |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesFrom Alert Triage to Threat Hunting: The New SOC Analyst Priority
Ask a SOC leader what changed after they turned on agentic triage, and you’ll usually get a quick answer: fewer alerts, faster decisions, maybe a new platform name. Ask what changed on the shift schedule, and the answer usually gets a lot less clear. Dave Kennedy laid out the what: deterministic work moves to agents, judgment work stays with the analyst, and three new responsibilities show up on the SOC floor. I want to talk about the part that gets less attention: when that work actually happens.
Dindoor - The Technical Analysis of an Iranian Backdoor
Dindoor is a backdoor that abuses the Deno runtime to execute malware within a target environment. Rather than shipping its own interpreter, Dindoor relies on Deno, a legitimate and widely used JavaScript and TypeScript runtime, and will install that runtime on the victim machine on demand if it is not already present. Using a signed, mainstream developer tool as its execution engine is the detail that sets Dindoor apart.
Binary Defense Names Industry Veteran Rafal Los as Chief Strategy Officer
CLEVELAND – July 28, 2026 – Binary Defense, the trusted Managed Detection and Response (MDR) and enterprise defense provider, today announced the appointment of Rafal Los as Chief Strategy Officer. In this role, Los will report directly to CEO and Founder David Kennedy and lead market-facing strategy across sales, sales engineering, customer success, marketing, channel, and technology alliances while helping expand Binary Defense's voice across the broader cybersecurity community.
The Queue Was Never the Job
Walk into almost any security operations center and the first thing you'll see is a queue. A list of alerts, ranked by severity, waiting for a human to work them from the top. The whole operation is organized around emptying that list faster than it fills. We hire against it, we build shift schedules around it, we measure analysts on how quickly they acknowledge and close it. For about twenty years, the queue has been the job. Start with the arithmetic, because it's brutal.
The Analyst's New Job Description
The Tines 2025 Voice of the SOC Analyst report found that 71% of SOC analysts report burnout and 64% are considering leaving within the year. The SANS 2025 SOC Survey found that satisfaction with generative AI tools ranks last among SOC technologies. Those two numbers tell the same story from different angles. The analyst job is being squeezed between two pressures. The deterministic work is moving to agents, which is good, because that's where most of the burnout was coming from.
BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities
A full-featured backdoor with file encryption, drive wiping, and a C2 channel that looks like normal message broker traffic. Meet BLUERABBIT, this Golang-based backdoor, attributed to a likely Iran-nexus threat actor, routes its command-and-control through RabbitMQ (AMQP) for tasking, Redis for state management, and MinIO for S3-compatible data exfiltration.
Machines Triage. Humans Decide.
The AI-orchestrated cyberespionage campaign that Anthropic disclosed in late 2025, the most agentic offensive operation publicly documented, required humans at four to six decision points per campaign. The attackers had every incentive to run the operation fully autonomously. They kept humans in the loop anyway, for the calls that mattered. They knew where the AI couldn't be trusted to decide. That same structural question is the one defenders have to answer.
Attackers Went Agentic First
Mandiant's M-Trends 2026 report puts the median time from initial access to handoff to a secondary threat group at 22 seconds in 2025. In 2022, that same median sat above eight hours. What changed is not that attackers got smarter. What changed is that initial access brokers started pre-staging secondary group malware before the handoff, turning what used to be a marketplace transaction into an automated delivery pipeline. The number is a readout on an assembly line, not a creativity contest.
The Metric to Anchor Your Agentic SOC Evaluation On
AI is fundamentally changing how we run security operations. I see it inside our own SOC every day. Analysts are going deeper on the work that matters because the routine work moves faster. The agentic wave is the next step in that change, and there's real promise in it. But the way the industry evaluates agentic SOC products hasn't caught up with what those products are doing. That's the gap I want to walk through here. The category is moving fast and the technology is genuinely impressive.
Chasing Phantoms: How a Multi-Stage Stealer Abuses Signed Binaries to Disappear
Information stealers continue to be one of the most prolific and damaging malware categories facing organizations today. They are fast, lightweight, and purpose-built to siphon credentials, session tokens, and financial data before defenders have time to respond.