Doogree
Living blog — updated as the system evolves

How to Build a Cyber Platform for SMBs — Transparently

For every technology decision we explain: what it is, why we chose it, what we compared, how we tested it, and how we keep improving it with quality control. We reveal the knowledge — never the secrets.

Monitoring · SIEM

From Isolated Alerts to One Attack Picture

A correlation engine that binds four signal streams by entity and time into a single incident with an attack chain — instead of an alert flood. Automatic escalation and a daily SOC report.

07/06/2026 · Monitoring
Offense · Deception

Honeytokens: 100%-Certain Intrusion Detection

A decoy an attacker touches = a verified intrusion, zero false alarms. 100% agentless — a cloud beacon that detects, enriches and alerts, then returns an innocent GIF.

07/06/2026 · Deception
Defense · NDR

Catching Lateral Movement Before It Reaches the Crown Jewels

Detecting east-west movement (a new internal peer on SMB/RDP = T1021) and logon-DNA for servers (a new account / an admin login from an unknown source = account takeover).

07/06/2026 · NDR
Response · Remediation

Fix With Consent: Remediating Without Crossing the Line

Every issue becomes an approve/reject button that triggers a named, reversible, gated action over a signed TOFU control channel — no free shell, with a full audit.

07/06/2026 · Response
DevSec · shift-left

Catching the Secret Before the Commit

One local-first engine that catches passwords and vulnerabilities as you type — in the editor, in the AI agent, and in git — without the code leaving the machine. AI agents, too, are blocked before they write a secret.

07/02/2026 · Technical Depth
Offense · Purple-Team

Attacking Yourself to Prove the Defense Works

Controlled attack campaigns (target×method) with a signed authorization gate, and every detection mapped to MITRE ATT&CK — to prove the alert actually fires, in seconds.

07/02/2026 · Security Depth
Compliance · Amendment 13

Amendment 13 — A Practical Checklist for Businesses

What the law requires and how to close each requirement in practice — mapping, controls, access management, audit trail, backup, incident reporting, and a one-click compliance report.

07/02/2026 · Compliance
Defense · Anomaly Detection

UEBA: Learn Normal, Catch Strange

How the engine learns the ordinary behavior of every device and alerts on deviation — a new peer, C2, an unsigned process, an off-hours login — with MITRE tagging.

07/02/2026 · Technical Depth
Cloud & Identities · Trust Model

Monitoring the Cloud Without Stealing Keys

Why other tools ask for your cloud keys, and how we scan AWS/Azure/GCP/M365/Google read-only — the keys stay with you.

07/02/2026 · Trust Model
Architecture · Permissions

Ownership, Device Sharing and a Per-Tenant API

Every user is a separate tenant with their own devices. Explicit per-device sharing, delete for owners only, a per-tenant API and MCP, and a 3D connections map.

06/30/2026 · Architecture
Overview · GROUND ZERO

What We've Built So Far — and Why This Way

One platform that unifies remote control, endpoint security, backup and a vault. The philosophy: one agent, one pane, the keys with the customer, and ~95% margins.

06/30/2026 · Big-Picture Overview
Backup · Technology Choice

Ransomware-Proof Backup: Why We Chose Kopia and Backblaze B2

A backup an attacker can delete is worthless. We compared 11 OSS engines and 4 storage providers, and reached an unambiguous conclusion on true Object-Lock.

06/30/2026 · Technical Depth
AI · Architecture

The Defensive Brain: Why Claude + Foundation-Sec-8B + RAG

We chose models by real benchmarks — not by hype. And we learned a counterintuitive insight: expensive reasoning doesn't improve cyber analysis.

06/30/2026 · Technical Depth
Security · Trust Model

An Unforgeable Control Channel: TOFU + Asymmetric Signing

Why a "rotating internal password" isn't enough, and why asymmetric signing + key pinning is stronger — even if our cloud is breached.

06/30/2026 · Security Depth

This blog is alive — we'll add articles on every new capability (UEBA, Amendment-13 compliance, purple-team, the "jail"/quarantine, and more). Each article reveals the reasoning and the comparison, but never secrets, keys, or details that would help an attacker.