- ThreatShadow Identities: The Common Attack Target You Can't See
How Command Zero addresses shadow identities
October 2025 · 7 min readRead → - Microsoft Teams Becomes the New Vishing Battleground
Microsoft Teams has recently emerged as a critical attack vector for sophisticated ransomware campaigns, with threat actors weaponizing enterprise communication platforms through coordinated vishing o
September 2025 · 5 min readRead → - Beyond Replacement: How AI Creates Super Analysts
After three years of AI implementations in security operations, the evidence is clear: artificial intelligence transforms SOC analysts into "super analysts" rather than replacing them. While AI excels
July 2025 · 5 min readRead → - Reality Check: Hype vs What Actually Works in AI for SOC
The AI revolution in security operations is here, but marketing promises far exceed current reality. After three decades building security software, the ground truth is clear: AI's value lies in augme
June 2025 · 5 min readRead → - Command Zero Named Top 10 Finalist for RSAC 2025 Innovation Sandbox: A Milestone in Our Mission to Transform Security Operations
Command Zero has been named one of the Top 10 Finalists for the prestigious RSAC 2025 Innovation Sandbox contest. This recognition represents a significant milestone in our journey to revolutionize Se
April 2025 · 4 min readRead → - InvestigationsInvestigate password spray attacks with accuracy and speed
What makes password spray attacks still dangerous in 2026?
January 2025 · 7 min readRead → - InvestigationsRevolutionizing cybersecurity investigations with expert questions and AI
How a question-based investigation compares with alternative methods
January 2025 · 10 min readRead → - NewsIntroducing Command Zero & Why focusing on tier-2+ is the best investment for security operations
Today, Command Zero is coming out of stealth, ready to revolutionize security operations.
July 2024 · 6 min readRead → - ProductBringing investigation intelligence into your existing workflows
SOC managers face a frustrating choice: force analysts to leave their trusted workflows to use a new tool, or let a powerful capability go underutilized.
May 2026 · 2 min readRead → - SOCAccelerate Supply Chain Investigations With Federated Data
A Different Approach: Evidence Before Inference
April 2026 · 4 min readRead → - EventsRSAC 2026: AI SOC Claims Finally Meet Operational Reality
Command Zero spent the week in working sessions with SOC leads and detection engineers. The consistent pressure point was the same: federated, source-agnostic access is the operational requirement.
April 2026 · 3 min readRead → - SOCSan Francisco, We’re Coming for You: Meet Command Zero During RSAC 2026
Other Must-Attend Community Events
March 2026 · 3 min readRead → - SOCThe Blind Spot at the Front Door: Why Identity-Hopping Attackers Are Invisible to Legacy SOCs
The Front Door Is Wide Open. Why Legacy SOC Architecture Can’t Keep Up.
March 2026 · 8 min readRead → - If Your AI SOC Can’t Show Its Work, You’ve Got a Compliance Problem Coming
The era of unregulated "black box" AI in security operations is ending due to new legal frameworks like the EU AI Act. With the EU Act now enforceable law and full compliance for high-risk systems req
February 2026 · 7 min readRead → - InvestigationsThe Federated Truth: Why Data Lakes Are Failing Investigations
The Future of Investigation Architecture
January 2026 · 16 min readRead → - AIThe Black Box SOC AI Agent Problem (And How to Fix It)
Security Operations Centers face a difficult paradox where AI agents offer necessary speed but create unacceptable liability due to their "black box" nature. CISOs remain hesitant to deploy these auto
January 2026 · 13 min readRead → - Investigating Service Principal Attacks with Graph API Activity Logs
Service principal attacks are escalating, with threat actors like Midnight Blizzard and Storm-0501 exploiting non-human identities to compromise enterprise environments. These attacks historically suc
December 2025 · 5 min readRead → - SOCThe AI SOC Paradox: Why Organizational Architecture Matters More Than Algorithm Performance
The barrier to AI-powered security operations isn't model sophistication—it's fragmented architectures across 83+ security tools that create impossible environments for autonomous agents to navigate.
December 2025 · 12 min readRead → - AIAnthropic's GTG-1002 disclosure: When AI Becomes a Cyber Weapon of Mass Destruction, Investigation Capabilities Must Scale
This is the Moment Command Zero is Built For
November 2025 · 17 min readRead → - Finding Your Way Upstream: Breaking the Burnout Cycle in Security Operations
During my twenty-plus years defending networks—from the Air Force to government contractor work to my current role in security research—I've watched exceptional analysts burn out from a systemic probl
November 2025 · 8 min readRead → - SOCThe SOC of the Future Is Already Here: Why Security Leaders Can't Risk Waiting to Adopt AI
After three decades building security software and leading multiple successful exits, I can tell you with certainty: AI in Security Operations Centers isn't a future consideration—it's an urgent prese
October 2025 · 12 min readRead → - NewsInvestigating Microsoft 365 Direct Send Abuse: When Convenience Becomes a Vulnerability
Real-World Impact: Get to Answers in Minutes, not Hours
October 2025 · 8 min readRead → - InvestigationsInvestigating Business Email Compromise: How Modern Attacks Exploit Trust in 2025
BEC Has Transformed, So Should Your Response
October 2025 · 15 min readRead → - Business Context: The Key Ingredient for Autonomous Security Operations
The promise of AI agents in security operations hinges on a deceptively simple question: Can AI SOC agents reliably make the same judgment calls as your most experienced analysts? Surprisingly, the an
October 2025 · 5 min readRead →
See what your team can achieve.
Live in under an hour. No migration. No friction.























