- Deep Dive: Finding and Investigating Microsoft Teams Vishing Attacks with Command Zero
Attackers exploit Microsoft Teams through sophisticated vishing campaigns that traditional security tools fail to detect. Command Zero addresses this critical gap with a comprehensive investigation pl
October 2025 · 10 min readRead → - SOCThe AI SOC Revolution: From Disparate Tools to Intelligent Defense
During my two decades defending networks and investigating threats, I've never witnessed transformation this profound. AI is revolutionizing security operations unlike any other tectonic shift has don
July 2025 · 6 min readRead → - NewsScattered Spider 2025 Update: The Social Engineering Threat That Won't Go Away
Fighting Scattered Spider with Command Zero
July 2025 · 7 min readRead → - SOCThe Evolution of SOC Structure: From Rigid Tiers to Flexible Operations
Picking the right tier structure for your SOC
June 2025 · 5 min readRead → - Breaking the SOC Alert Fatigue Cycle: Why Speed Metrics Are Killing Quality
Security operations centers face a critical crisis: alert fatigue is overwhelming analysts and creating dangerous investigation gaps. Traditional SOC metrics like MTTR and MTTI incentivize speed over
June 2025 · 5 min readRead → - ProductCommand Zero & Okta Identity Threat Protection: Level-up Identity Investigations
Level-up identity investigations
May 2025 · 3 min readRead → - Introducing the Agent Communication & Discovery Protocol (ACDP): A proposal for AI agents to discover and collaborate with each other
AI agents are becoming increasingly specialized and numerous, creating an urgent need for standardized methods of discovery and collaboration. Without a standardized protocol that enables secure disco
April 2025 · 16 min readRead → - SOCWhy SIEMs and data lakes do not deliver the optimal experience for security investigations
Centralized data systems like SIEMs and data lakes excel at detection, reporting and compliance, but fall short for complex security investigations.
April 2025 · 5 min readRead → - InvestigationsInvestigating Risky Sign-ins: Getting to the right answers fast
Investigative challenges around risky sign-ins
March 2025 · 7 min readRead → - Control Validation: Uncovering Tactical Drift in SecOps
Control validation addresses a critical vulnerability in modern security operations—the gap between deployed security measures and their actual effectiveness. This post explores how tactical drift occ
March 2025 · 5 min readRead → - InvestigationsInvestigating Locked Accounts: Making sense of the canary in the coal mine
Streamlining locked account investigations with Command Zero
March 2025 · 5 min readRead → - GitHub Investigations: Securing the Foundation of Modern Innovation
As software development accelerates through DevOps processes, GitHub repositories have become both invaluable intellectual property stores and potential attack vectors. Threat actors increasingly expl
February 2025 · 5 min readRead → - ProductEmail Investigations: The Epicenter of Security Analysis
The hard truth: Emails are full user identities
February 2025 · 6 min readRead → - AISecuring LLM-Backed Systems: A Guide to CSA’s Authorization Best Practices
How Command Zero secures LLM-backed systems
February 2025 · 7 min readRead → - ThreatOperationalizing threat intelligence at scale: Challenges and solutions
The Command Zero experience vs. legacy investigation flows
January 2025 · 8 min readRead → - 2024 Learnings and 2025 Predictions Through Frequently Asked Questions
What we predict for 2025 based on these FAQs
December 2024 · 6 min readRead → - ProductNavigating complexity with structure: Using pre-built sequences for security investigations
Running facets within investigations
December 2024 · 7 min readRead → - AwardsTop challenges in security operations and recommendations for SecOps leaders
This post wraps up our blog series for Command Zero's recent research report. The report exposed critical cybersecurity investigation challenges across 15 industries. Key findings from 352 professiona
December 2024 · 6 min readRead → - InvestigationsInvestigations lack consistency, documentation and auditabilityNovember 2024 · 8 min readRead →
- Current SecOps tools are hard to operate and investigate
Despite the early and sincere focus on search/investigations, modern SIEM and SOAR capabilities have evolved to satisfy compliance/regulatory requirements. Today, these technologies do not provide ded
October 2024 · 7 min readRead → - An interview with Eric Hulse: Insights from recent Command Zero engagements
In this interview, we dive deep into the world of cybersecurity investigations with Eric Hulse, Head of Research at Command Zero. Eric shares invaluable insights from some of the recent customer engag
October 2024 · 6 min readRead → - ResearchUncertain security alerts: Common hurdles and recommendations
A typical day in the life of a security analyst
October 2024 · 9 min readRead → - ResearchUniversal talent gap in cybersecurity hinders the ability to run investigationsOctober 2024 · 6 min readRead →
- IdentityThe Goal, Scope and Methodology of Command Zero’s Recent Research on Cyber Investigations
Command Zero published its first research report: “Top Challenges in Cyber Investigations & Recommendations for SecOps Leaders” on September 10, 2024. The report is based on 352 interviews with cyber
October 2024 · 4 min readRead →
See what your team can achieve.
Live in under an hour. No migration. No friction.























