SOC Prime

The only Threat Detection Marketplace where researchers monetize their content to help security teams defend against attacks faster and more efficiently.

2025-11-03

The russian hackers target Ukraine again in new campaigns against a major business services company and a local state body using LotL and dual-use tools & a custom Sandworm-linked webshell. Detect attacks with Sigma rules from SOC Prime Platform.

socprime.com/blog/russian-hack

2025-10-31

Security isn’t a checkbox — it’s who we are. SOC Prime has achieved SOC 2 Type II compliance for the 5th year in a row, proving our continued dedication to the highest security standards.

👉 Read more: socprime.com/news/soc-prime-5-

2025-10-30

CVE-2025-59287, a new critical RCE vulnerability in Microsoft WSUS systems, is under active exploitation. With a PoC out, rapid detection is a must. Timely spot exploitation attempts with curated detections from SOC Prime Platform.
socprime.com/blog/cve-2025-592

2025-10-22

Complex attacks don’t follow a straight line — are you seeing the full chain?

Attack Flow v3.0.0 by Center for Threat-Informed Defense is a game-changing approach to visualizing threat behavior. SOC Prime takes it further.

🔗 socprime.com/blog/attack-flow-

#mirte #cybersecurity #threatintelligence

2025-10-16

CERT-UA reports a new spearphishing campaign by UA-0239 targeting the Ukrainian Defense Forces and local government bodies, deploying OrcaC2 and FILEMESS stealer. Detect attacks with curated Sigma rules available in the SOC Prime Platform.
socprime.com/blog/uac-0239-att

2025-10-10

Storm-1175 group exploits CVE-2025-10035, a critical GoAnywhere MFT vulnerability enabling command injection & RCE, followed by deployment of Medusa ransomware. Stay ahead of the threat with curated detection content from SOC Prime Platform.
socprime.com/blog/detect-cve-2

2025-10-08

Oracle has released an emergency update to address a critical RCE vulnerability (CVE-2025-61882) in its E-Business Suite, which has been actively exploited in recent Cl0p ransomware data theft attacks. Detect potential exploitation attempts using a set of Sigma rules in the SOC Prime Platform.

socprime.com/blog/cve-2025-618

2025-10-03

AI ransomware on the rise! FunkLocker is a new AI-based ransomware strain by FunkLocker that has already hit 100+ organizations in the U.S., Europe, and Asia. Stay ahead of ransomware attacks with curated detection rules from SOC Prime Platform.
socprime.com/blog/detect-funkl

2025-10-02

CERT-UA warns defenders of targeted attacks against the Ukrainian military entities by the UAC-0245 threat group using CABINETRAT backdoor spread via Excel XLL add-ins shared over Signal. Detect malicious activity with Sigma rules in the SOC Prime Platform.
socprime.com/blog/detect-uac-0

2025-09-30

Rely on zero-trust, multi-cloud, and cost-efficient security operations backed by AWS and SOC Prime innovation to future-proof your cyber resilience.
my.socprime.com/amazon-web-ser

2025-09-29

Detect BRICKSTORM, a stealthy backdoor used by China-nexus UNC5221 APT in targeted cyber-espionage campaigns against U.S. legal & tech firms, with the latest CTI and curated Sigma rules in the SOC Prime Platform.

socprime.com/blog/brickstorm-b

2025-09-24

The latest CISA alert warns of a major threat posed by CVE-2024-36401, an unauthenticated RCE vulnerability in GeoServer exploited to breach a U.S. federal agency. Detect related TTPs using a set of Sigma rules in the SOC Prime Platform.
socprime.com/blog/detect-attac

2025-09-17

Outsmart adversaries with SOC Prime's hands-on training based on real-life scenarios. Dive into critical concepts, improve practical skills, and accelerate threat hunting and detection engineering maturity through enhanced expertise.

Learn more: my.socprime.com/detection-engi

2025-09-16

Maranhão Stealer targets gamers via cloud-hosted pirated software, using social engineering, reflective DLL injection, and advanced stealth methods to hijack credentials and crypto wallets. Detect attacks with Sigma rules from SOC Prime Platform.
socprime.com/blog/maranhao-ste

2025-09-11

The new Gentlemen ransomware group exploits privileged accounts and evades defenses with advanced techniques targeting critical organizations in 17+ countries. Proactively detect ransomware attacks with curated Sigma rules from SOC Prime Platform.
socprime.com/blog/the-gentleme

2025-09-10

Knowledge Bits are bite-sized insights by SOC Prime experts to resolve common SIEM, EDR, and Data Lake hurdles.
Dive in now: socprime.com/blog/#knowledge_b

2025-09-09

Detect MostereRAT attacks, a stealthy phishing-driven threat leveraging AnyDesk and TightVNC to sustain long-term control over compromised Windows systems, using Sigma rules in the SOC Prime Platform.
socprime.com/blog/mostere-rat-

2025-08-29

Join SOC Prime's Discord community to be the first to know about emerging threats and network with cybersecurity experts.

Start now: discord.gg/ec6JQbPbzb

2025-08-26

New BQTLOCK ransomware operates as RaaS and uses advanced detection evasion techniques to stay under the radar. Proactively detect emerging ransomware attacks using curated Sigma rules from SOC Prime Platform.
socprime.com/blog/bqtlock-rans

2025-08-18

Crypto24 ransomware group hits high-profile organizations across the US, Europe, and Asia using a mix of legitimate tools and custom malware to stay under the radar. Detect sophisticated ransomware attacks with Sigma rules from SOC Prime Platform.
socprime.com/blog/crypto24-ran

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst