• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • About Me
  • Privacy Policy
  • Media Mentions

PenTestIT.com

Your source for Detection Engineering, Security Research and Adversary Simulation

  • Search Engine Dorks
  • RSS feed
You are here: Home / Archives for 2026

Archives for 2026

Essential Detection Engineering Metrics

Detection Engineering

Essential Detection Engineering Metrics

This is a list of essential detection engineering metrics.

Posted: Sep 1, 2026 by Mayuresh @pentestit
Updated: Sep 9, 2026

You have prioritized your threat detection backlog, but now want to quantify the progress. Throughout my career leading multiple threat detection engineering teams, I have relied on well-defined metrics to measure outcomes, demonstrate program value, and drive continuous improvement. In this post, I outline the detection engineering metrics I consider most important, spanning Read more about Essential Detection Engineering Metrics

Detection Engineering

“Severity” or “Expected Severity” for Prioritization?

This post introduce the concept of "Expected Severity" for threat prioritization.

Posted: Apr 26, 2026 by Mayuresh @pentestit 721 views
Updated: Sep 6, 2026

In one of my last post - Prioritizing a Threat Detection Backlog, I talked about prioritizing your threat detection backlog. It is true when you run a program in an organization. However, when you consume security content from another organization, severity is often generalized. This is where, the concept of expected severity can help and I trust should be used more often. Let Read more about “Severity” or “Expected Severity” for Prioritization?

Microsoft Patch Tuesday March 2026

Vulnerability Management

Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority

This blog is my interpretation of the Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority.

Posted: Mar 11, 2026 by Mayuresh @pentestit 1,169 views
Updated: Sep 12, 2026

This Microsoft Patch Tuesday March 2026 release addressed 93 vulnerabilities across Windows, Office, SQL Server, .NET, and Azure. Interestingly, two CVEs were publicly disclosed pre‑patch CVE‑2026‑21262 (SQL Server EoP) and CVE‑2026‑26127 (.NET DoS). However, unlike last month, no March CVE is confirmed exploited in the wild as of today. What is unusual is the fact that six of Read more about Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority

List of Open Source C2 Post-Exploitation Frameworks

Offensive Security

List of Open Source C2 Post-Exploitation Frameworks

This is a list of open source C2 post-exploitation frameworks.

Posted: Feb 16, 2026 by Mayuresh @pentestit 1,371 views
Updated: Oct 1, 2026

Restoring this post with the help of the Wayback machine - This post has been lying in my drafts for more than a year with edits all over. But two days ago, it was announced that Powershell Empire would no longer be supported by it’s authors. Hence just like I curated a list of adversary emulation tools, I finalized this list of open source C2 post-exploitation Read more about List of Open Source C2 Post-Exploitation Frameworks

Adversary Emulation

List of Adversary Emulation Tools

This is a list of open source and commercial adversary emulation tools

Posted: Feb 12, 2026 by Mayuresh @pentestit 1,316 views
Updated: Sep 11, 2026

As I went through the logs on this blog, I saw that an old post from 2018 was still being requested for! Thanks to the internet gods, I was able to find a cached copy. Currently, this is a paste of the old adversary emulation post as is. But, I will update it in a few days time. Every once in a while, the security industry brings forth a new buzz word and introduces Read more about List of Adversary Emulation Tools

Detection Engineering

Prioritizing a Threat Detection Backlog

These are a few methods that you can use to prioritize a threat detection backlog

Posted: Feb 9, 2026 by Mayuresh @pentestit 1,092 views
Updated: Sep 6, 2026

Most security teams eventually hit the same problem - the list of “detections to build next” grows faster than the capacity to actually build, test, and maintain them. Inputs from red-team exercises, threat intelligence reports, new CVEs, leadership asks, compliance requirements, and plain hype can drive a perfect prioritization backlog haywire. Without a clear model for Read more about Prioritizing a Threat Detection Backlog

« Previous Page

Primary Sidebar

Add PenTestIT as a preferred source on Google

Recently Updated

  1. List of Open Source C2 Post-Exploitation FrameworksUpdated Oct 1, 2026
  2. Analysis: CVE-2026-88771 and CVE-2026-88772Updated Sep 29, 2026
  3. Deepstar: A Open Source Deepfake Detection ToolkitUpdated Sep 27, 2026
  4. List of Open Source Deepfake Detection ToolsUpdated Sep 27, 2026
  5. Claude Skill: threat-report-killchainUpdated Sep 21, 2026

Categories

  • Adversary Emulation
  • Cyber Threat Intelligence
  • Detection Engineering
  • Offensive Security
  • Open Source
  • Penetration Testing
  • Tools
  • Vulnerability Management
  • Vulnerability Research
  • Web Application Security

Archives

  • October 2026
  • September 2026
  • April 2026
  • March 2026
  • February 2026
  • August 2022
  • July 2020

Copyright © 2026 - PenTestIT.com | Information shared to be used for LEGAL purposes only!