AlphaSOC Blog
Security research, threat analysis, and product updates from the AlphaSOC team.
Six Ways to Catch npm Supply Chain Attacks
npm supply chain attacks increased in 2026, including a compromised axios package and a self-propagating worm. Here are six ways to detect them using network telemetry and install hygiene.

Enhanced Threat Detection with Sigma and AlphaSOC Wisdom
AlphaSOC Wisdom brings threat intelligence directly into Sigma rules, enriching detections with domain reputation, infrastructure type, and behavioral risk flags: no external feeds required.

Sigma Correlations in AlphaSOC
AlphaSOC now supports Sigma Correlations, linking multiple events over time to produce high-confidence OCSF findings for multi-stage attack patterns that individual rules miss.

Introducing the AlphaSOC Cribl Dashboard
The AlphaSOC for Cribl Search pack brings OCSF detection findings into a purpose-built dashboard for triage, entity analysis, and raw event inspection.

Azure Event Hubs Silently Truncates JSON Payloads
Azure Event Hubs truncates JSON logs that exceed undocumented size limits, appending "..." and producing invalid JSON with no error or warning. Here is how we found it and fixed it.

Finding Patient Zero With Security Analytics
Most detection stacks confirm compromise after the fact. Learn how prevalence analysis and correlation surface the earliest foothold before feeds catch up.