<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Dual-Strike XISEM]]></title><description><![CDATA[This substack is the place to learn whats new with Dual-Strike XISEM!]]></description><link>https://press.dual-strike.com</link><image><url>https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png</url><title>Dual-Strike XISEM</title><link>https://press.dual-strike.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 30 Jun 2026 21:44:48 GMT</lastBuildDate><atom:link href="https://press.dual-strike.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Vysion Technology Solutions LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dualstrikexisem@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dualstrikexisem@substack.com]]></itunes:email><itunes:name><![CDATA[Andrew Streetman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Andrew Streetman]]></itunes:author><googleplay:owner><![CDATA[dualstrikexisem@substack.com]]></googleplay:owner><googleplay:email><![CDATA[dualstrikexisem@substack.com]]></googleplay:email><googleplay:author><![CDATA[Andrew Streetman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Essay: Why “evidence first” beats “alert first”]]></title><description><![CDATA[Subtitle: A field note for security leaders tired of buying another red dashboard.]]></description><link>https://press.dual-strike.com/p/essay-why-evidence-first-beats-alert-first</link><guid isPermaLink="false">https://press.dual-strike.com/p/essay-why-evidence-first-beats-alert-first</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:57:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> A field note for security leaders tired of buying another red dashboard.</p><div><hr></div><p>I have watched the same movie in a hundred SMB and mid-market environments: a new tool ships, plugs into one data source, paints everything Critical, and six months later the SOC mutes notifications. The tool is not evil. The <strong>model</strong> is wrong.</p><p>Dual-Strike XISEM is built on a different premise: <strong>evidence first, interpretation second, human decision third.</strong></p><h2>Alerts without evidence are opinions</h2><p>When a SIEM rule fires on a single syslog line, the analyst inherits a <strong>hypothesis</strong>. When Threat Center fires after agent harvest + browsing category + Entra sign-in anomaly, the analyst inherits a <strong>story</strong>. Stories close faster and survive audit.</p><h2>Collectors should not judge</h2><p>Your EDR contains malware. Your email gateway blocked phish. Your browser extension saw AI tool usage. Each is a <strong>fact</strong>. None alone is a verdict. The platform&#8217;s job is correlation &#8212; not to replace the EDR console or become a mail filter.</p><p>That separation is why we insist agents and extensions <strong>prove</strong> rather than <strong>punish</strong>. Anti-Venom telemetry does not block the CEO&#8217;s browser because a model said so in the cloud &#8212; policy tiers and human-authored rules do, with session evidence visible in Browsing Insights.</p><h2>Posture is a conversation, not a scoreboard</h2><p>ASPIRE letter grades exist so a vCISO can sit with a client and say: <strong>&#8220;Security pillar dropped because EDR agent fell off three laptops &#8212; here they are.&#8221;</strong> Not: <strong>&#8220;Risk score 73.&#8221;</strong> Numbers without pillars are vanity.</p><h2>Compliance is continuous, not annual panic</h2><p>Framework mapping only hurts when it is a January spreadsheet. Tie controls to <strong>live evidence</strong> &#8212; patch state, identity disablement, extension coverage &#8212; and POA&amp;M becomes a <strong>running backlog</strong>, not a fire drill before the auditor arrives.</p><h2>MSPs win on narrative</h2><p>Your clients buy <strong>outcomes</strong>: fewer incidents, faster recovery, audit confidence, browser visibility in the AI era. They do not buy &#8220;another integration.&#8221; Dual-Strike XISEM gives you one narrative across agent, browser, identity, EDR, and PSA &#8212; so your QBR slides tell a story, not a vendor laundry list.</p><h2>Practical takeaway</h2><p>Next time you evaluate or tune the stack:</p><ol><li><p>Ask <strong>what evidence</strong> a detection requires before it pages someone</p></li><li><p>Ask <strong>which pillar</strong> moved when posture changes</p></li><li><p>Ask <strong>what closes the loop</strong> in PSA &#8212; not just what opens the alert</p></li></ol><p>Evidence first is slower on day one and quieter on day thirty. That is the point.</p><p><strong>Explore:</strong> Evidence doctrine infographic &#183; Asset modal guide &#183; <a href="https://dual-strike.com">dual-strike.com</a></p><div><hr></div><p><em>Opinion piece &#8212; product architecture aligns with Dual-Strike XISEM doctrine published in Support wiki.</em></p>]]></content:encoded></item><item><title><![CDATA[The Asset modal: your investigative console]]></title><description><![CDATA[Subtitle: Timelines, matrices, and narratives &#8212; built for analysts, auditors, and engineers.]]></description><link>https://press.dual-strike.com/p/the-asset-modal-your-investigative-console</link><guid isPermaLink="false">https://press.dual-strike.com/p/the-asset-modal-your-investigative-console</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:55:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Timelines, matrices, and narratives &#8212; built for analysts, auditors, and engineers.</p><div><hr></div><p>Dual-Strike XISEM UI philosophy: <strong>intelligence surfaces</strong>, not alert engines. The <strong>Asset modal</strong> is the clearest expression of that &#8212; a single-device (or single-identity) console where evidence converges before anyone opens a PSA ticket.</p><h2>What opens when you click an asset</h2><p>SurfacePurpose <strong>Overview</strong>ASPIRE grade, last seen, agent version, location class <strong>Timeline</strong>Correlated events &#8212; agent, browser, identity, detections <strong>Extension Health</strong>Per-browser status, last session, idle vs stale tiers <strong>Matrices</strong>Posture and CA evaluation snapshots <strong>Compliance</strong>Control mappings tied to this asset&#8217;s evidence <strong>Pivots</strong>Jump to user, related detections, browsing sessions</p><p>No tab is a standalone &#8220;warning light.&#8221; Each is <strong>evidence with context</strong>.</p><h2>Investigation flow (example)</h2><p><strong>Scenario:</strong> Shadow AI detection on a sales laptop.</p><ol><li><p>Threat Center &#8594; open detection &#8594; pivot to <strong>Asset modal</strong></p></li><li><p>Timeline shows browser sessions to unsanctioned AI tool <strong>before</strong> EDR saw anything</p></li><li><p>Extension Health confirms Edge reporting (not a coverage gap)</p></li><li><p>Identity tab links Entra user for CA policy review</p></li><li><p>Create PSA ticket with evidence summary pre-filled</p></li><li><p>After remediation, close ticket &#8212; status syncs back</p></li></ol><h2>Who uses it</h2><ul><li><p><strong>SOC analysts</strong> &#8212; first stop after alert triage</p></li><li><p><strong>vCISOs</strong> &#8212; QBR screenshots (redact client names)</p></li><li><p><strong>Auditors</strong> &#8212; control evidence drill-down</p></li><li><p><strong>Engineers</strong> &#8212; agent version, harvest gaps, extension deploy issues</p></li></ul><h2>Capture tips for your runbooks</h2><p>When documenting client procedures, screenshot <strong>Overview + Timeline</strong> with:</p><ul><li><p>Client display name redacted or replaced with &#8220;Demo Org&#8221;</p></li><li><p>User emails hashed or removed</p></li><li><p>Real hostnames replaced with <code>CLIENT-WS-###</code> pattern</p></li></ul><p>We ship demo-style illustrations in this newsletter; your Substack posts can swap in live redacted captures.</p><p><strong>Route:</strong> Inventory &#8594; any managed asset &#8594; opens modal</p><p><strong>Related:</strong> ASPIRE scoring post &#183; Browsing Insights field guide</p><div><hr></div><p><em>Platform layer interprets harvester evidence &#8212; the modal never fabricates telemetry.</em></p>]]></content:encoded></item><item><title><![CDATA[Network topology: see the map behind the assets]]></title><description><![CDATA[Subtitle: Discovery, segments, and posture &#8212; correlated with agents and identity.]]></description><link>https://press.dual-strike.com/p/network-topology-see-the-map-behind-the-assets</link><guid isPermaLink="false">https://press.dual-strike.com/p/network-topology-see-the-map-behind-the-assets</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:55:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Discovery, segments, and posture &#8212; correlated with agents and identity.</p><div><hr></div><p>Endpoints do not float in vacuum. <strong>Network topology</strong> in Dual-Strike XISEM visualizes <strong>how assets connect</strong>: sites, VLANs, gateways, VPN paths, and discovered neighbors &#8212; correlated with agent inventory and identity sessions.</p><p><strong>Route:</strong> <code>/network</code> &#183; Support wiki &#8594; Network topology &amp; discovery</p><h2>Evidence sources for topology</h2><p>SourceContribution <strong>XISEM agent</strong>Local adapters, routes, DNS, peer discovery <strong>Network device infeeds</strong>Fortinet, UniFi, Meraki-class integrations (per wiki) <strong>Identity location</strong>Office / home / unknown classification <strong>Manual site tags</strong>Client org site definitions</p><p>Platform layer <strong>interprets</strong> harvester and integration evidence &#8212; it does not scan the network independently of collectors.</p><h2>Operator use cases</h2><ol><li><p><strong>Incident scope</strong> &#8212; &#8220;What subnet was this laptop on when detection fired?&#8221;</p></li><li><p><strong>Segmentation audit</strong> &#8212; server VLAN reachable from guest Wi-Fi?</p></li><li><p><strong>Asset context</strong> &#8212; Asset modal shows network attachment alongside ASPIRE</p></li><li><p><strong>Compliance</strong> &#8212; network boundary controls (NIST SC family, PCI segmentation)</p></li></ol><h2>MSP workflow</h2><ol><li><p>Deploy agents to representative sites (HQ, branch, remote)</p></li><li><p>Connect <strong>firewall/switch</strong> integration where client owns supported gear</p></li><li><p>Review <strong>topology graph</strong> for orphan nodes (discovered but not managed)</p></li><li><p>Align orphan list with <strong>Inventory</strong> onboarding campaign</p></li></ol><h2>Limitations (honest)</h2><ul><li><p>Cloud-only workloads may appear as <strong>identity + SaaS</strong> signals rather than L2 map</p></li><li><p>Remote workers often show <strong>home/unknown</strong> location class &#8212; pair with Browsing Insights</p></li><li><p>Discovery depth depends on agent and integration coverage &#8212; not a replacement for dedicated NDR (roadmap items public on wiki)</p></li></ul><p><strong>Related:</strong> ASPIRE Environment pillar &#183; CVE correlation post</p><div><hr></div><p><em>No internal scan schedules or credential storage details &#8212; configure integrations in-console.</em></p>]]></content:encoded></item><item><title><![CDATA[Threat intelligence feeds: IOCs that meet your assets]]></title><description><![CDATA[Subtitle: External feeds + internal telemetry &#8212; correlated, not copy-pasted into spreadsheets.]]></description><link>https://press.dual-strike.com/p/threat-intelligence-feeds-iocs-that-meet-your-assets</link><guid isPermaLink="false">https://press.dual-strike.com/p/threat-intelligence-feeds-iocs-that-meet-your-assets</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:55:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> External feeds + internal telemetry &#8212; correlated, not copy-pasted into spreadsheets.</p><div><hr></div><p>Dual-Strike XISEM <strong>Threat Intelligence</strong> integrations ingest <strong>IOC feeds</strong> (hashes, domains, IPs, URLs) and match them against <strong>agent harvests</strong>, <strong>DNS logs</strong>, <strong>browsing sessions</strong>, and <strong>EDR exports</strong>. Matches elevate in <strong>Threat Center</strong> and can trigger <strong>COBRA&#178;</strong> rules.</p><p><strong>Route:</strong> Settings &#8594; Threat Intelligence &#183; Support wiki &#8594; Threat intelligence feeds</p><h2>Feed types</h2><p>TypeExample sources (wiki index) <strong>Commercial TI</strong>Partner feeds via API <strong>Open source</strong>STIX/TAXII compatible lists <strong>ISAC / sector</strong>Client-specific sharing agreements <strong>Internal</strong>Your own block lists from prior incidents</p><h2>Match surfaces</h2><ul><li><p><strong>Browsing Insights</strong> &#8212; domain/URL reputation hits</p></li><li><p><strong>Asset modal</strong> &#8212; file hash on disk vs. feed</p></li><li><p><strong>Network</strong> &#8212; DNS query to known C2 domain</p></li><li><p><strong>Email</strong> &#8212; attachment hash from Proofpoint/M365 path</p></li></ul><h2>Tuning for false positives</h2><ol><li><p>Start feeds in <strong>alert-only</strong> mode per client</p></li><li><p>Require <strong>2-of-N</strong> correlation for auto-ticket (e.g., DNS hit + process execution)</p></li><li><p>Exclude known CDN domains via MSP baseline exception list</p></li><li><p>Review weekly <strong>top matched IOCs</strong> &#8212; retire stale entries</p></li></ol><h2>MSP differentiator</h2><p>Most SMB clients cannot operate a TI platform. You operationalize feeds <strong>once</strong> at MSP tier, inherit downstream to clients with appropriate <strong>data sharing</strong> contracts.</p><h2>Compliance angle</h2><p>Threat intelligence usage satisfies <strong>monitoring and analysis</strong> controls in NIST, SOC 2, and CMMC when documented with <strong>feed source</strong>, <strong>update cadence</strong>, and <strong>match response</strong> procedures.</p><p><strong>Related:</strong> COBRA&#178; guide &#183; Email security layer &#183; Threat Center</p><div><hr></div><p><em>Feed credentials stored per integration policy &#8212; never publish API keys in newsletters.</em></p>]]></content:encoded></item><item><title><![CDATA[Anti-Venom policy hierarchy: six tiers explained]]></title><description><![CDATA[Subtitle: Global defaults, MSP overrides, client rules &#8212; predictable browser governance at scale.]]></description><link>https://press.dual-strike.com/p/anti-venom-policy-hierarchy-six-tiers-explained</link><guid isPermaLink="false">https://press.dual-strike.com/p/anti-venom-policy-hierarchy-six-tiers-explained</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:54:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Global defaults, MSP overrides, client rules &#8212; predictable browser governance at scale.</p><div><hr></div><p><strong>Anti-Venom Secure Access</strong> applies policy from a <strong>six-tier hierarchy</strong>. Higher specificity wins. MSPs managing dozens of clients rely on this model to ship <strong>one baseline</strong> and <strong>per-client exceptions</strong> without redeploying extensions.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NWcu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWcu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 424w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 848w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 1272w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWcu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Anti-Venom deployment flow from agent to detection&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Anti-Venom deployment flow from agent to detection" title="Anti-Venom deployment flow from agent to detection" srcset="https://substackcdn.com/image/fetch/$s_!NWcu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 424w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 848w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 1272w, https://substackcdn.com/image/fetch/$s_!NWcu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F154f6433-6e8b-41ee-906b-c208e5d116cc_960x360.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Anti-Venom deployment flow from agent to detection</figcaption></figure></div><h2>The six tiers (high &#8594; low precedence)</h2><ol><li><p><strong>Client org exception</strong> &#8212; single-customer rule (e.g., allow industry portal)</p></li><li><p><strong>Client org policy</strong> &#8212; default browser posture for that customer</p></li><li><p><strong>MSP org override</strong> &#8212; your standard across all clients unless excepted</p></li><li><p><strong>Platform template</strong> &#8212; Dual-Strike published baselines (AI tools, risky categories)</p></li><li><p><strong>Agent local relay</strong> &#8212; offline/cache path when using LocalApi-first mode</p></li><li><p><strong>Extension built-in safe defaults</strong> &#8212; fail-closed for unknown categories</p></li></ol><p>Exact tier names in-console may vary slightly &#8212; precedence order is what matters.</p><h2>What policies control</h2><p>CategoryExample <strong>AI tools</strong>Allow Copilot, warn on consumer ChatGPT <strong>Risky domains</strong>Block phishing tiers, warn on new domains <strong>SaaS catalog</strong>Sanctioned vs. shadow IT labels <strong>Business hours</strong>Stricter rules outside 9&#8211;5 local <strong>Telemetry</strong>Session upload via agent relay vs. direct</p><h2>Deployment flow (recap)</h2><ol><li><p><strong>Agent</strong> on endpoint (MSI or RMM)</p></li><li><p><strong>Extension</strong> from browser store (Edge GA highlighted in prior post)</p></li><li><p><strong>Policy publish</strong> in console &#8212; extensions poll on interval</p></li><li><p><strong>Browsing Insights</strong> validates sessions and categories</p></li><li><p><strong>COBRA&#178;</strong> consumes categories for detections</p></li></ol><h2>MSP pattern: golden template</h2><ol><li><p>Define <strong>MSP tier</strong> once &#8212; AI warn, risky block, SaaS tag</p></li><li><p>Clone to new client org on onboarding</p></li><li><p>Add <strong>client exceptions</strong> only for documented business apps</p></li><li><p>Review <strong>Browsing Insights top domains</strong> quarterly &#8212; promote shadow IT to sanctioned or block</p></li></ol><p><strong>Settings:</strong> Browser Extension &#183; <strong>Insights:</strong> <code>/browsing-insights</code></p><p><strong>Downloads:</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>Prefer agent relay at scale &#8212; reduces per-device cloud chatter (public architecture guidance only).</em></p>]]></content:encoded></item><item><title><![CDATA[Pivot Analyst Workbench: cross-source hunting without SQL]]></title><description><![CDATA[Subtitle: Pre-built pivots from any evidence object &#8212; browser session to identity to detection in three clicks.]]></description><link>https://press.dual-strike.com/p/pivot-analyst-workbench-cross-source-hunting-without-sql</link><guid isPermaLink="false">https://press.dual-strike.com/p/pivot-analyst-workbench-cross-source-hunting-without-sql</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:53:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Pre-built pivots from any evidence object &#8212; browser session to identity to detection in three clicks.</p><div><hr></div><p>Tier 2 analysts lose hours context-switching between EDR, Entra, PSA, and spreadsheet exports. The <strong>Pivot Analyst Workbench</strong> (public name in product wiki) is Dual-Strike XISEM&#8217;s <strong>structured hunting layer</strong>: start from any evidence object and follow <strong>platform-defined pivots</strong> without writing queries.</p><p><strong>Route:</strong> Asset modal &#8594; Pivot &#183; Threat Center &#8594; Investigate &#183; Support wiki &#8594; Pivot analyst workbench</p><h2>Entry points</h2><p>Start fromCommon pivots <strong>Browser session</strong>User, device, related detections, domain prevalence <strong>Entra sign-in</strong>Device, location class, mailbox rules, COBRA hits <strong>Detection</strong>All contributing signals, affected assets, PSA ticket <strong>File hash</strong>Other assets with hash, TI feed match, process tree (EDR) <strong>CVE</strong>Affected assets, patch status, network exposure</p><h2>Workbench vs. Investigations</h2><ul><li><p><strong>Workbench</strong> &#8212; exploratory, ephemeral trail while analyst thinks</p></li><li><p><strong>Investigations</strong> &#8212; persistent case with notes and assignee</p></li></ul><p>Promote workbench trail to Investigation when you know you have a case.</p><h2>MSP hunting playbooks (public)</h2><p><strong>Shadow AI hunt</strong></p><ol><li><p>Browsing Insights &#8594; filter AI category &#8594; open session</p></li><li><p>Pivot user &#8594; all AI domains 30d</p></li><li><p>Pivot detections &#8594; COBRA shadow AI rules</p></li><li><p>Create Investigation + PSA ticket</p></li></ol><p><strong>BEC hunt</strong></p><ol><li><p>Email integration &#8594; suspicious rule change</p></li><li><p>Pivot identity &#8594; sign-ins + mailbox</p></li><li><p>Pivot browsing &#8594; OAuth grants</p></li><li><p>Escalate Critical if dual control failed</p></li></ol><h2>Training new analysts</h2><p>Workbench teaches <strong>correlation paths</strong> native to Dual-Strike XISEM &#8212; faster ramp than teaching five vendor consoles. Pair with <strong>COBRA&#178; guide</strong> and <strong>Asset modal</strong> post for onboarding curriculum.</p><h2>Limits (honest)</h2><ul><li><p>Pivots require <strong>infeed coverage</strong> &#8212; no Entra pivots without GDAP</p></li><li><p>Historical depth follows <strong>retention policy</strong> &#8212; long hunts may need exported reports</p></li><li><p>Workbench does not replace EDR <strong>process graph</strong> for deep malware analysis &#8212; pivot into vendor console when containment needed</p></li></ul><p><strong>Related:</strong> Investigations workflow &#183; Browsing Insights &#183; Threat intelligence feeds</p><div><hr></div><p><em>Workbench pivot catalog expands per release &#8212; in-console menu is authoritative.</em></p>]]></content:encoded></item><item><title><![CDATA[POA&M generation: from gaps to owned remediation]]></title><description><![CDATA[Subtitle: Plan of Action & Milestones &#8212; exportable, PSA-aware, audit-ready.]]></description><link>https://press.dual-strike.com/p/poa-m-generation-from-gaps-to-owned-remediation</link><guid isPermaLink="false">https://press.dual-strike.com/p/poa-m-generation-from-gaps-to-owned-remediation</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 30 Jun 2026 18:52:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Plan of Action &amp; Milestones &#8212; exportable, PSA-aware, audit-ready.</p><div><hr></div><p>Compliance assessments fail when gaps live in email threads. Dual-Strike XISEM <strong>POA&amp;M</strong> (Plan of Action &amp; Milestones) generation turns <strong>compliance gaps</strong>, <strong>detection findings</strong>, and <strong>manual auditor notes</strong> into tracked remediation items with owners, due dates, and evidence of closure.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://press.dual-strike.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Dual-Strike XISEM! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Route:</strong> Compliance &#8594; POA&amp;M &#183; Support wiki &#8594; Compliance getting started</p><h2>POA&amp;M item anatomy</h2><p>FieldPurpose <strong>Control reference</strong>Framework + control ID <strong>Gap description</strong>Plain language <strong>Severity</strong>Critical &#8594; low <strong>Owner</strong>Client or MSP assignee <strong>Due date</strong>Milestone tracking <strong>Evidence of closure</strong>Linked detection resolved, patch proof, config screenshot <strong>PSA ticket</strong>When outfeed enabled</p><h2>Generation sources</h2><ol><li><p><strong>Automated</strong> &#8212; compliance scan finds partial/not met control</p></li><li><p><strong>Detection-promoted</strong> &#8212; Critical COBRA finding &#8594; POA&amp;M row</p></li><li><p><strong>Manual</strong> &#8212; auditor adds item during assessment</p></li><li><p><strong>Bulk import</strong> &#8212; spreadsheet template (in-console)</p></li></ol><h2>Monthly vCISO rhythm</h2><ol><li><p>Export <strong>open POA&amp;M</strong> PDF for client steering committee</p></li><li><p>Sort overdue items &#8594; PSA escalation</p></li><li><p>Close items only with <strong>evidence attachment</strong> (agent harvest, report snapshot)</p></li><li><p>Trend <strong>open count</strong> down &#8212; executive binder widget</p></li></ol><h2>Auditor conversation</h2><p>Auditors want <strong>traceability</strong>:</p><p>&gt; &#8220;Show me control AC-2 partial &#8212; what opened it, who owns it, what proved closure.&#8221;</p><p>POA&amp;M row links satisfy that without rebuilding binders each visit.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0EGB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0EGB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 424w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 848w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 1272w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0EGB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Compliance framework coverage supports POA&amp;M control references&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Compliance framework coverage supports POA&amp;M control references" title="Compliance framework coverage supports POA&amp;M control references" srcset="https://substackcdn.com/image/fetch/$s_!0EGB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 424w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 848w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 1272w, https://substackcdn.com/image/fetch/$s_!0EGB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397dd1da-16ee-4726-87ac-904f5b285b2d_960x360.svg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Compliance framework coverage supports POA&amp;M control references</figcaption></figure></div><p><strong>Related:</strong> Compliance mapping 100+ frameworks &#183; Reports &#183; Client portal</p><div><hr></div><p><em>POA&amp;M exports redact internal analyst notes marked MSP-private when configured.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://press.dual-strike.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Dual-Strike XISEM! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[File Integrity Monitoring — from agent hash to Threat Center tab]]></title><description><![CDATA[Subtitle: SAM, SECURITY, SYSTEM, and hosts &#8212; baselined on every Windows security harvest.]]></description><link>https://press.dual-strike.com/p/file-integrity-monitoring-from-agent-hash-to-threat-center-tabhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/file-integrity-monitoring-from-agent-hash-to-threat-center-tabhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Wed, 10 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> SAM, SECURITY, SYSTEM, and hosts &#8212; baselined on every Windows security harvest.</p><div><hr></div><p>Compliance frameworks ask whether critical system files <strong>changed</strong>. Traditional FIM agents are heavy, noisy, and often deployed on servers only.</p><p><strong>Dual-Strike XISEM 8.8.0</strong> closes the loop: <strong>agent collection &#8594; platform ingest &#8594; Threat Center File Integrity tab &#8594; alert path</strong> for high/critical changes.</p><h2>What the agent watches (Windows default)</h2><p>When <code>WatchPaths</code> is empty, the Windows agent hashes on each security harvest (~15 min):</p><ul><li><p><code>C:\Windows\System32\config\SAM</code></p></li><li><p><code>C:\Windows\System32\config\SECURITY</code></p></li><li><p><code>C:\Windows\System32\config\SYSTEM</code></p></li><li><p><code>C:\Windows\System32\drivers\etc\hosts</code></p></li></ul><p>Configurable via <strong><code>Agent:FileIntegrity</code></strong> in agent settings.</p><h2>What analysts see</h2><ul><li><p><strong>Threat Center &#8594; File Integrity</strong> &#8212; baselines, changes, analyst explainer copy</p></li><li><p>High/critical path changes continue through existing alert logic</p></li><li><p>Compliance mapping for PCI-DSS, HIPAA, SOC 2-style controls where FIM evidence applies</p></li></ul><h2>Deploy checklist (public)</h2><ol><li><p>Upgrade to <strong>Dual-Strike XISEM Agent 8.8.0</strong> GA line when promoted in your channel</p></li><li><p>Confirm one security harvest cycle completes</p></li><li><p>Open File Integrity &#8212; expect <strong>four tracked files per Windows endpoint</strong> at baseline</p></li></ol><p><strong>Downloads:</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>Ship when 8.8.0 GA is your fleet standard &#8212; adjust version callout if publishing before GA promotion.</em></p>]]></content:encoded></item><item><title><![CDATA[Shadow AI isn’t a policy PDF — it’s a browsing signal]]></title><description><![CDATA[Subtitle: See ChatGPT, Copilot, and Claude usage in Browsing Insights before the board asks.]]></description><link>https://press.dual-strike.com/p/shadow-ai-isn-t-a-policy-pdf-it-s-a-browsing-signalhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/shadow-ai-isn-t-a-policy-pdf-it-s-a-browsing-signalhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 09 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> See ChatGPT, Copilot, and Claude usage in Browsing Insights before the board asks.</p><div><hr></div><p>Every client leadership team got the memo: <em>&#8220;We need an AI policy.&#8221;</em></p><p>Few got the telemetry: <em>&#8220;Who used which AI tool, from which device, with what data exposure risk?&#8221;</em></p><p><strong>Dual-Strike XISEM</strong> classifies <strong>AI tool sessions</strong> in Anti-Venom browsing telemetry and surfaces them in <strong>Browsing Insights</strong> and <strong>COBRA&#178;</strong> detection paths.</p><h2>What we detect (conceptually)</h2><ul><li><p>Sessions to known AI SaaS domains (ChatGPT, Microsoft Copilot, Claude, Gemini, etc.)</p></li><li><p>Duration and frequency &#8212; not just &#8220;someone visited once&#8221;</p></li><li><p>Correlation with <strong>identity</strong>, <strong>device posture</strong>, and <strong>location class</strong></p></li><li><p>Optional COBRA rules for unsanctioned AI on regulated endpoints</p></li></ul><h2>Why agent + extension matter</h2><p>Browser-only DLP misses context. <strong>Anti-Venom</strong> paired with the <strong>XISEM Agent</strong> gives:</p><ul><li><p>Authenticated user correlation where identity infeeds exist</p></li><li><p>Policy enforcement paths (warn / block / watermark) when you move from learning to enforce</p></li><li><p>Agent relay for scalable ingest</p></li></ul><h2>Operator playbook</h2><ol><li><p>Roll extension in <strong>learning mode</strong> &#8212; collect two weeks of AI usage</p></li><li><p><strong>Browsing Insights</strong> &#8594; filter AI tool sessions &#8594; export talking points for client steering committee</p></li><li><p>Define sanctioned vs unsanctioned tools in <strong>browser policy</strong></p></li><li><p>Enable COBRA detection for high-risk combinations (e.g., AI tool + file-share category same session window)</p></li></ol><h2>The conversation shift</h2><p>Instead of <em>&#8220;We banned AI,&#8221;</em> you bring <em>&#8220;Here&#8217;s who used what, here&#8217;s the policy tier, here&#8217;s what we blocked this month with evidence.&#8221;</em></p><p>That&#8217;s how security teams stay credible while the business adopts AI anyway.</p><p><strong>Start:</strong> Anti-Venom rollout &#8594; Browsing Insights &#8594; <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>AI domain classification updates with threat intel and SaaS catalogs &#8212; confirm categories in-console for your scope.</em></p>]]></content:encoded></item><item><title><![CDATA[Conditional Access intelligence — without locking you into Entra]]></title><description><![CDATA[Subtitle: Vendor-agnostic policy evaluation from correlated evidence, not agent guesswork.]]></description><link>https://press.dual-strike.com/p/conditional-access-intelligence-without-locking-you-into-entrahtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/conditional-access-intelligence-without-locking-you-into-entrahtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 08 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Vendor-agnostic policy evaluation from correlated evidence, not agent guesswork.</p><div><hr></div><p>&#8220;Conditional Access&#8221; became synonymous with Microsoft Entra. But <strong>access decisions</strong> in real organizations depend on more than IdP signals: <strong>where</strong> the device is, <strong>what</strong> the endpoint posture is, <strong>whether</strong> the browser extension attests, <strong>what</strong> EDR last saw.</p><p><strong>Dual-Strike XISEM Conditional Access intelligence</strong> is a <strong>platform-level abstraction</strong> &#8212; client-org scoped, <strong>not</strong> tied to a single vendor console.</p><h2>What it evaluates</h2><p>Policies express <strong>scope</strong> (asset types, identity types), <strong>conditions</strong> (location class, risk tier, posture signals), and <strong>actions</strong> (restrict, block, step-up, isolate, monitor).</p><p>Default templates include patterns operators recognize:</p><ul><li><p>Block privileged access from unknown locations</p></li><li><p>Step-up auth when identity appears from home network with drift</p></li><li><p>Read-only posture during geo anomalies</p></li></ul><p>Evaluations are logged for audit &#8212; auditable outcomes, not silent blocks in an agent.</p><h2>Where you see it</h2><ul><li><p><strong>Compliance</strong> console &#8594; Conditional Access tab</p></li><li><p><strong>Asset modal</strong> &#8594; correlated CA posture alongside evidence timelines</p></li><li><p><strong>MIP overview</strong> &#8594; CAA / attestation coverage rollup</p></li></ul><h2>Why MSPs care</h2><p>Clients ask: <em>&#8220;Are we zero trust?&#8221;</em> You need a answer that doesn&#8217;t require exporting Entra CA to a spreadsheet and hand-waving device trust.</p><p>XISEM <strong>correlates harvester evidence</strong> (location, agent health, extension attestation, identity) into <strong>policy evaluations</strong> your analysts can explain in a QBR &#8212; and map to compliance frameworks already in the platform.</p><h2>Not enforcement &#8212; intelligence</h2><p>Dual-Strike XISEM <strong>does not replace</strong> Entra CA enforcement at the IdP. It <strong>informs</strong> decisions: detections, investigations, POA&amp;M items, and client reporting.</p><p>That separation matters: the platform stays evidence-driven; enforcement stays where admins already configure it.</p><p><strong>Explore:</strong> Compliance &#8594; Conditional Access &#183; <a href="https://dual-strike.com">dual-strike.com</a></p><div><hr></div><p><em>Policy templates evolve with releases &#8212; use in-console descriptions as ground truth.</em></p>]]></content:encoded></item><item><title><![CDATA[Did you know? The greatest barrier to a functional IT team isn’t the tools]]></title><description><![CDATA[Subtitle: It&#8217;s how they&#8217;re used &#8212; and whether they agree on what &#8220;secure&#8221; means.]]></description><link>https://press.dual-strike.com/p/did-you-know-the-greatest-barrier-to-a-functional-it-team-isn-t-the-toolshtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/did-you-know-the-greatest-barrier-to-a-functional-it-team-isn-t-the-toolshtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Sun, 07 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> It&#8217;s how they&#8217;re used &#8212; and whether they agree on what &#8220;secure&#8221; means.</p><div><hr></div><p>We sell a platform. This post isn&#8217;t a pitch &#8212; it&#8217;s a pattern we see in every mature MSP and internal IT org:</p><p><strong>Tool count correlates weakly with outcomes. Integration depth correlates strongly.</strong></p><h2>The sprawl trap</h2><p>A typical mid-market client stack in 2026:</p><ul><li><p>RMM + PSA</p></li><li><p>M365 + Entra</p></li><li><p>EDR</p></li><li><p>Email security</p></li><li><p>Backup</p></li><li><p>Maybe a SIEM someone bought and never finished</p></li><li><p>Maybe a &#8220;browser security&#8221; SKU that nobody checks</p></li></ul><p>Each tool has <strong>its own alert language</strong>, <strong>its own asset ID</strong>, <strong>its own ticket queue</strong>. Technicians become human ETL pipelines: copy hostname from A, paste into B, hope the user email matches.</p><p>Security doesn&#8217;t fail because you lack a dashboard. It fails because <strong>no dashboard owns the narrative</strong>.</p><h2>What &#8220;working together&#8221; actually means</h2><p>Not &#8220;we have an API.&#8221; Working together means:</p><ol><li><p><strong>One asset identity</strong> &#8212; serial, Entra device ID, agent ID, and PSA company map to the same row</p></li><li><p><strong>One severity story</strong> &#8212; detection in XISEM &#8594; ticket in ConnectWise &#8594; close syncs back</p></li><li><p><strong>One identity story</strong> &#8212; leaver in HR &#8594; MIP lifecycle &#8594; session revoke + license review</p></li><li><p><strong>One browsing story</strong> &#8212; risky SaaS in Anti-Venom &#8594; Browsing Insights &#8594; COBRA rule &#8594; client QBR slide</p></li></ol><p>When those chains exist, <strong>junior techs execute playbooks</strong>. When they don&#8217;t, <strong>senior people burn out triaging contradictions</strong>.</p><h2>Posture is a team sport</h2><p>We built Dual-Strike XISEM around <strong>evidence doctrine</strong>: collectors prove facts; the platform interprets; humans decide.</p><p>That only works if:</p><ul><li><p><strong>Agents</strong> report consistently (patch the straggler before debating SIEM rules)</p></li><li><p><strong>Extensions</strong> are store-deployed and agent-paired (not ghost 6.x profiles)</p></li><li><p><strong>Identity infeeds</strong> are connected before you claim &#8220;zero trust&#8221;</p></li><li><p><strong>PSA tickets</strong> close when the incident closes &#8212; or metrics lie</p></li></ul><p>The organizations that win treat integrations as <strong>operating procedures</strong>, not checkboxes on a sales deck.</p><h2>A practical Monday exercise</h2><p>Pick <strong>one client</strong>. Trace <strong>one user</strong> through:</p><ul><li><p>Entra sign-in &#8594; asset in XISEM &#8594; browsing session &#8594; open detection &#8594; PSA ticket</p></li></ul><p>Where does the chain break? Fix <strong>that</strong> before buying tool #12.</p><div><hr></div><p>We&#8217;ll keep shipping releases (8.7.x, MIP, PSA paths, Edge store). The teams that extract value will be the ones that <strong>wire</strong> them &#8212; not the ones with the longest vendor list.</p><p><strong>If you want the platform side of that wiring:</strong> <a href="https://dual-strike.com/demo">dual-strike.com/demo</a></p>]]></content:encoded></item><item><title><![CDATA[Browsing Insights: see what your users actually do in the browser]]></title><description><![CDATA[Subtitle: SaaS discovery, AI-tool usage, and policy outcomes &#8212; without another agent on the wire.]]></description><link>https://press.dual-strike.com/p/browsing-insights-see-what-your-users-actually-do-in-the-browserhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/browsing-insights-see-what-your-users-actually-do-in-the-browserhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Sat, 06 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> SaaS discovery, AI-tool usage, and policy outcomes &#8212; without another agent on the wire.</p><div><hr></div><p>You have EDR. You have email security. You still don&#8217;t know which <strong>SaaS apps</strong>, <strong>AI tools</strong>, or <strong>risky domains</strong> your users hit in the browser until something shows up on a credit report.</p><p><strong>Browsing Insights</strong> is the Dual-Strike XISEM console for <strong>web session telemetry</strong> from <strong>Anti-Venom Secure Access</strong> &#8212; duration, categories, AI classification, risky flags, business-hours context, and investigation pivots.</p><p><strong>Route:</strong> <code>/browsing-insights</code></p><h2>What you see</h2><p>ViewOperator use <strong>Sessions over time</strong>Volume trends &#8212; did rollout work? <strong>Top domains / SaaS</strong>Shadow IT and unsanctioned apps <strong>AI tool usage</strong>ChatGPT, Copilot, Claude, etc. <strong>Risky / blocked</strong>Policy and reputation hits <strong>By user / by device</strong>Investigation starting points <strong>Extension Health</strong>Which browsers report, which don&#8217;t</p><p>Data flows from Anti-Venom (direct cloud or <strong>agent relay</strong> &#8212; preferred at scale).</p><h2>How it fits the stack</h2><ol><li><p>Deploy <strong>Dual-Strike XISEM Agent</strong> on the endpoint</p></li><li><p>Deploy <strong>Anti-Venom</strong> (Chrome, Edge, or Firefox &#8212; store GA on 8.7.x)</p></li><li><p>Publish <strong>browser policy</strong> in Settings &#8594; Browser Extension</p></li><li><p>Open <strong>Browsing Insights</strong> &#8212; filter by client, user, domain, time range</p></li></ol><p>No manual Supabase URLs for end users. Production posture is <strong>agent-gated</strong>.</p><h2>Recent improvements (8.7.0.17 platform)</h2><ul><li><p>Reliable session loading at <strong>MSP multi-client scope</strong></p></li><li><p><strong>24-hour default</strong> time window (better Monday reviews)</p></li><li><p><strong>Extension Health</strong> weekend grace &#8212; spare laptops aren&#8217;t false &#8220;not detected&#8221; alarms</p></li></ul><h2>Tie-in to detections</h2><p>Browser events feed <strong>COBRA&#178;</strong> rules: shadow AI, DLP-class categories, exfil patterns. Turn on browsing first; tune detections second.</p><h2>Start here</h2><ol><li><p>Pick one pilot client with agent + extension deployed</p></li><li><p>Confirm <strong>Extension Health</strong> shows green/idle &#8212; not &#8220;not detected&#8221;</p></li><li><p>Review <strong>top domains</strong> and <strong>AI sessions</strong> for a week</p></li><li><p>Add one COBRA rule for your highest-risk category</p></li></ol><p><strong>Docs path:</strong> Support wiki &#8594; Anti-Venom &amp; Browsing Insights &#183; <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>Retention follows platform policy &#8212; aggregate reporting for large fleets should use rollups where available.</em></p>]]></content:encoded></item><item><title><![CDATA[New RMM & PSA integrations — tickets that write themselves (almost)]]></title><description><![CDATA[Subtitle: ConnectWise, Autotask, Halo, SuperOps, NinjaOne, Syncro, Freshservice, Zendesk, ServiceNow, Jira, and more &#8212; one dispatch fabric.]]></description><link>https://press.dual-strike.com/p/new-rmm-psa-integrations-tickets-that-write-themselves-almosthtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/new-rmm-psa-integrations-tickets-that-write-themselves-almosthtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Fri, 05 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> ConnectWise, Autotask, Halo, SuperOps, NinjaOne, Syncro, Freshservice, Zendesk, ServiceNow, Jira, and more &#8212; one dispatch fabric.</p><div><hr></div><p>Your SOC finds something real. Then someone copies a title into ConnectWise. Then the ticket closes in the PSA but stays open in the SIEM. Then nobody trusts either system.</p><p><strong>Dual-Strike XISEM PSA integrations</strong> exist to break that loop: <strong>native ticket create, bidirectional close sync, and client mapping</strong> from the same console where detections and alerts already live.</p><h2>What&#8217;s supported today</h2><p>Configure at <strong><code>/integrations/psa</code></strong> (MSP credentials + per-client company mapping):</p><p>PlatformNative API / path <strong>ConnectWise Manage</strong>REST <strong>Autotask</strong>REST <strong>Syncro MSP</strong>REST <strong>Halo PSA</strong>OAuth REST <strong>SuperOps</strong>GraphQL <strong>NinjaOne</strong>OAuth REST <strong>Freshservice</strong>REST <strong>Zendesk</strong>REST <strong>ServiceNow</strong>REST <strong>Jira Service Management</strong>Atlassian REST <strong>Console (console.com)</strong>Webhook playbook <strong>N-able N-central</strong>Custom PSA webhook <strong>Custom webhook</strong>JSON POST to your middleware</p><h2>What gets ticketed</h2><p>You choose rules &#8212; not a firehose:</p><ul><li><p><strong>COBRA&#178; detections &amp; threats</strong> (primary path from the Threats console)</p></li><li><p><strong>Alerts</strong> (with optional skip when already backed by a detection &#8212; avoids duplicates)</p></li><li><p><strong>High/critical security events</strong></p></li><li><p><strong>CVE correlation hits</strong></p></li><li><p><strong>OSINT threat-actor overlap</strong> with client telemetry</p></li><li><p><strong>Manual &#8220;Create Ticket&#8221;</strong> from any investigation</p></li></ul><p>Rate limits (<code>max tickets per hour/day</code>) keep noisy environments from spamming the PSA.</p><h2>Bidirectional sync</h2><p>When a ticket <strong>closes in the PSA</strong>, XISEM can <strong>resolve the linked detection/alert</strong> &#8212; and when XISEM resolves, the PSA ticket updates too. Scheduled sync keeps status from drifting for days.</p><h2>RMM context (not just tickets)</h2><p>Beyond PSA, Dual-Strike XISEM ingests from <strong>SuperOps</strong>, <strong>NinjaOne</strong>, <strong>SentinelOne</strong> (MSP site maps), <strong>Hudu</strong>, <strong>Huntress</strong>, <strong>DNSFilter</strong>, and the <strong>XISEM agent</strong> fleet itself &#8212; so asset identity in the console matches how you already organize clients in the RMM.</p><p><strong>Infeeds &amp; integrations</strong> live at <code>/infeeds</code> and <code>/msp-tenants</code> depending on vendor (MSP vs client scope).</p><h2>Monday-morning setup (15-minute version)</h2><ol><li><p><strong>PSA Integrations</strong> &#8594; pick your PSA tab &#8594; enter MSP API credentials &#8594; <strong>Test</strong></p></li><li><p><strong>Client Mapping</strong> &#8594; link each PSA company to a XISEM client</p></li><li><p><strong>Ticket rules</strong> &#8594; enable detections + alerts at your minimum severity</p></li><li><p>Fire a test detection in a lab client &#8594; confirm ticket lands in the right queue</p></li></ol><h2>Why this post belongs in a security newsletter</h2><p>Integrations aren&#8217;t checkbox features. They&#8217;re <strong>posture multipliers</strong>: the same signal that drives compliance evidence should drive <strong>work your technicians already do</strong> &#8212; in the tool they already live in.</p><p><strong>Explore integrations:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; console <strong>PSA Integrations</strong></p><div><hr></div><p><em>Exact tab labels and vendor OAuth flows evolve &#8212; use in-console setup wizards as ground truth.</em></p>]]></content:encoded></item><item><title><![CDATA[Dual-Strike XISEM now ships a full Managed Identity Provider — including NHI governance]]></title><description><![CDATA[Subtitle: Humans get lifecycle and reviews.]]></description><link>https://press.dual-strike.com/p/dual-strike-xisem-now-ships-a-full-managed-identity-provider-including-nhi-goverhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/dual-strike-xisem-now-ships-a-full-managed-identity-provider-including-nhi-goverhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Thu, 04 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Humans get lifecycle and reviews. Service accounts, API keys, and OAuth grants get the same discipline.</p><div><hr></div><p>Identity programs usually stop at <strong>people</strong>.</p><p>Meanwhile, the breach story moved to <strong>non-human identities (NHIs)</strong> &#8212; service principals, API keys, OAuth consents, workload identities, automation accounts, and &#8220;temporary&#8221; integration users that never left.</p><p><strong>Dual-Strike XISEM Managed Identity Provider (MIP)</strong> is our answer: one console for <strong>joiner-mover-leaver</strong>, <strong>privileged access</strong>, <strong>access reviews</strong>, <strong>ITDR</strong>, and <strong>NHI governance</strong> &#8212; without replacing Microsoft Entra, Okta, or Google Workspace. We correlate and govern <strong>across</strong> them.</p><h2>What MIP is (one sentence)</h2><p><strong>MIP is identity governance and ITDR posture for scoped clients</strong> &#8212; lifecycle rollups, risk signals, certifications, and evidence bound to frameworks &#8212; in <code>/identity/mip</code>.</p><h2>The pillars operators care about</h2><h3>Identity lifecycle (JML)</h3><p><strong>Joiner &#8594; Mover &#8594; Leaver</strong> state machine with visibility into who&#8217;s active, suspended, or still licensed after offboarding. Stale leavers are where auditors and attackers overlap.</p><h3>SCIM 2.0 provisioning</h3><p>Bidirectional connectors for <strong>Entra ID, Okta, and Google Workspace</strong>. One MIP fabric; multiple directories.</p><h3>Privileged Identity Management (JIT)</h3><p>Just-in-time elevation with ticket-bound approval, time limits, and automatic revocation &#8212; <strong>standing privilege trending toward zero</strong>.</p><h3>Access reviews &amp; certification</h3><p>Quarterly (or custom) campaigns: approve, deny, delegate. Decisions land in a <strong>tamper-evident audit warehouse</strong> &#8212; not a spreadsheet.</p><h3>ITDR &#8212; identity threat detection</h3><p>Detect-first, recommend-first signals: token theft patterns, OAuth consent abuse, MFA fatigue, dormant accounts, weak-MFA exposure &#8212; with analyst-ready actions (session revoke, MFA reset, role drop).</p><h3>OAuth &amp; SaaS app risk</h3><p>Continuous discovery of consented apps and third-party connectors &#8212; publisher trust, scope risk, and footprint in one tier.</p><h3>Role mining &amp; Segregation of Duties</h3><p>Jaccard clustering suggests roles from entitlement patterns; <strong>SoD</strong> rule packs flag toxic combinations (finance vs IT admin vs audit).</p><h2>NHI governance &#8212; the part most &#8220;IG&#8221; products hand-wave</h2><p><strong>Non-Human Identity governance</strong> in MIP covers:</p><p>NHI typeWhat MIP tracks Service principals &amp; app registrationsOwnership, last use, excessive scopes API keys &amp; secretsRotation age, stale credentials OAuth grants &amp; workload identitiesOrphan detection, consent drift Automation / integration accountsDormant flags, privilege weight</p><p><strong>Why it matters:</strong> NHIs don&#8217;t show up in HR offboarding. They accumulate in Azure, SaaS marketplaces, and PSA webhooks &#8212; until something exfiltrates data with a key that &#8220;was always there.&#8221;</p><p>MIP gives NHIs <strong>inventory, risk context, and audit lineage</strong> next to human identities &#8212; so your access review program isn&#8217;t blind to half the attack surface.</p><h2>Compliance binding (without a separate GRC project)</h2><p>MIP actions map to evidence for <strong>NIST 800-53, CMMC 2.0, SOC 2, and ISO 27001</strong> &#8212; AC, IA, AU, and IR families &#8212; auto-bound where the platform observes identity events.</p><h2>Who this is for</h2><ul><li><p><strong>MSPs/MSSPs</strong> standardizing identity posture across clients</p></li><li><p><strong>vCISOs</strong> who need one pane for lifecycle + ITDR + certification</p></li><li><p><strong>Regulated clients</strong> (defense, finance, healthcare) where NHI and SoD are examiner questions &#8212; not trivia</p></li></ul><h2>Getting started</h2><ol><li><p>Connect identity infeeds (<strong>Microsoft GDAP / Entra</strong>, <strong>Okta</strong>, <strong>Google Workspace</strong>, <strong>Petra ITDR</strong> where used)</p></li><li><p>Open <strong>Identity (MIP)</strong> at client scope &#8212; review lifecycle outliers on the overview rollup</p></li><li><p>Enable <strong>access review</strong> campaigns and NHI inventory for high-risk clients first</p></li></ol><p><strong>Learn more:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; request a <strong>Managed Identity Provider</strong> demo</p><div><hr></div><p><em>MIP detects and recommends; your IdP remains authoritative for authentication. Dual-Strike XISEM is the intelligence and policy layer &#8212; not a replacement directory.</em></p>]]></content:encoded></item><item><title><![CDATA[Dual-Strike XISEM 8.7.0.17 is GA]]></title><description><![CDATA[Subtitle: Store extensions, smarter browsing reports, and extension health that respects real-world endpoints.]]></description><link>https://press.dual-strike.com/p/dual-strike-xisem-8-7-0-17-is-gahtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/dual-strike-xisem-8-7-0-17-is-gahtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Wed, 03 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Store extensions, smarter browsing reports, and extension health that respects real-world endpoints.</p><div><hr></div><p><strong>8.7.0.17</strong> is now the current General Availability line for <strong>Dual-Strike XISEM Agent</strong>, <strong>Anti-Venom Secure Access</strong> (Chrome, Edge, Firefox), and the <strong>platform console</strong> &#8212; one SemVer, one fleet story.</p><p>If you&#8217;ve been waiting for &#8220;store-primary Edge + stable browsing dashboards,&#8221; this is the build to standardize on.</p><h2>Highlights</h2><h3>Anti-Venom on all major desktop browsers (store GA)</h3><ul><li><p><strong>Chrome, Edge, and Firefox</strong> public store builds at <strong>8.7.0.17</strong></p></li><li><p>Enterprise Edge deployments benefit from store-trust and simplified Intune/Edge policy (see our Edge announcement post)</p></li><li><p>Agent bundles and RMM packages updated on <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p></li></ul><h3>Browsing Insights &#8212; data you can trust</h3><p>Operators told us the hard part wasn&#8217;t collecting sessions &#8212; it was <strong>seeing them in the console</strong> when scoped to an MSP with many clients.</p><p><strong>8.7.0.17 platform improvements:</strong></p><ul><li><p><strong>Browsing session views load reliably</strong> at MSP and client scope (no more empty &#8220;By Device / By User&#8221; when telemetry exists)</p></li><li><p><strong>Default time range widened to 24 hours</strong> so Monday-morning reviews include Friday activity</p></li><li><p><strong>Clear error banner</strong> when session load fails &#8212; with retry &#8212; instead of silent zeros</p></li></ul><p>Use <strong>Browsing Insights</strong> for SaaS discovery, AI-tool usage, risky domains, and investigation pivots per user or device.</p><h3>Extension Health &#8212; truthful, not noisy</h3><p>Spare laptops. Conference room PCs. &#8220;Nobody&#8217;s logged in since Thursday.&#8221;</p><p>Extension Health now <strong>distinguishes</strong>:</p><ul><li><p><strong>Healthy / idle extension telemetry</strong> (including weekend-scale agent check-ins)</p></li><li><p><strong>Actionable &#8220;extension not detected&#8221;</strong> &#8212; agent active in the last 24 hours, but no Chrome/Firefox/Edge extension reporting</p></li><li><p><strong>Endpoints idle 24&#8211;72 hours</strong> &#8212; not screamed as failures</p></li></ul><p>You get fewer false alarms and a shorter list of devices that actually need a store install or policy push.</p><h3>Security posture &amp; ASPIRE scoring</h3><p>Improvements to <strong>extension-attested posture</strong> and <strong>ASPIRE</strong> alignment &#8212; so Conditional Access and browsing evidence show up consistently in the asset narrative analysts already use (not a separate &#8220;mystery zero&#8221;).</p><h3>Agent delivery</h3><ul><li><p><strong>Windows MSI</strong> and Linux installer scripts on the downloads CDN</p></li><li><p>OTA/update checks point at the current GA artifact (upgrade path documented on Downloads)</p></li></ul><h2>Who should upgrade?</h2><p>RoleAction <strong>MSP operator</strong>Roll 8.7.0.17 agent + store extensions via RMM; verify Extension Health <strong>Analyst</strong>Re-open Browsing Insights after platform refresh &#8212; confirm session counts <strong>Client admin</strong>No action if your MSP manages agents; otherwise pull MSI from Downloads</p><h2>Upgrade path</h2><ol><li><p>Deploy <strong>Dual-Strike XISEM Agent 8.7.0.17</strong> (MSI or your RMM package)</p></li><li><p>Confirm <strong>Anti-Venom 8.7.0.17</strong> on Chrome / Edge / Firefox (store or enterprise policy)</p></li><li><p>Hard-refresh the console &#8212; validate <strong>Browsing Insights</strong> and <strong>Extension Health</strong></p></li></ol><p><strong>Get the build:</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>Platform-only updates apply on login &#8212; no agent install required for Browsing Insights and Extension Health UI fixes.</em></p>]]></content:encoded></item><item><title><![CDATA[Anti-Venom Secure Access is now on Microsoft Edge]]></title><description><![CDATA[Subtitle: Same policy engine as Chrome and Firefox &#8212; now one click away for Edge-first enterprises.]]></description><link>https://press.dual-strike.com/p/anti-venom-secure-access-is-now-on-microsoft-edgehtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/anti-venom-secure-access-is-now-on-microsoft-edgehtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 02 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Same policy engine as Chrome and Firefox &#8212; now one click away for Edge-first enterprises.</p><div><hr></div><p>Microsoft Edge is the default browser in a huge slice of the market: Entra-joined laptops, VDI pools, and &#8220;we standardized on Edge for compliance&#8221; shops. If your secure browsing policy only lived in Chrome, you were always one default-browser setting away from a gap.</p><p><strong>That gap closes today.</strong></p><p><strong>Anti-Venom Secure Access</strong> &#8212; the Dual-Strike XISEM browser extension &#8212; is available on the <strong>Microsoft Edge Add-ons</strong> store, alongside <strong>Chrome Web Store</strong> and <strong>Firefox Add-ons</strong>, aligned on the current <strong>8.7.x</strong> release line.</p><h2>What Anti-Venom does (in plain language)</h2><p>Anti-Venom is not a generic &#8220;web filter.&#8221; It&#8217;s the browser-side enforcement and telemetry layer for Dual-Strike XISEM:</p><ul><li><p><strong>Session visibility</strong> &#8212; domains, duration, AI-tool usage, risky categories (feeds <strong>Browsing Insights</strong>)</p></li><li><p><strong>Policy enforcement</strong> &#8212; allow, warn, and block with verdict watermarks your analysts can explain</p></li><li><p><strong>Agent-gated posture</strong> &#8212; production deployments pair the extension with the <strong>Dual-Strike XISEM Agent</strong> on the same endpoint so policy and telemetry stay under your control (LocalApi / agent relay paths &#8212; not ad-hoc user configuration)</p></li></ul><p>End users don&#8217;t paste API keys. MSPs deploy agent + extension through RMM, Intune, or store policy &#8212; the same playbook you already use for Chrome.</p><h2>Why Edge store matters</h2><p>Enterprise Edge deployments often block sideloads and unsigned CRX paths. Store distribution means:</p><ul><li><p><strong>Fewer &#8220;organization blocked this extension&#8221; tickets</strong></p></li><li><p><strong>Cleaner alignment with Intune / Edge management policies</strong></p></li><li><p><strong>One version line</strong> with Chrome and Firefox &#8212; no shadow 6.x installs fighting your 8.7 fleet</p></li></ul><h2>What to do</h2><ol><li><p>Confirm <strong>Dual-Strike XISEM Agent 8.7.x</strong> is deployed to the endpoint (extension expects the agent companion).</p></li><li><p>Deploy Anti-Venom from the <strong>Edge Add-ons</strong> listing (or your existing enterprise force-install policy pointing at store IDs).</p></li><li><p>Publish browser policy in <strong>Settings &#8594; Browser Extension</strong>; allow ~15 minutes for refresh.</p></li><li><p>Open <strong>Browsing Insights</strong> and <strong>Extension Health</strong> to confirm check-ins.</p></li></ol><p><strong>Downloads &amp; store links:</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><p>Questions about monitor vs protect modes or learning vs enforce? That&#8217;s a great follow-up post &#8212; reply here and we&#8217;ll cover deployment tiers next.</p>]]></content:encoded></item><item><title><![CDATA[Welcome to the Dual-Strike Dispatch]]></title><description><![CDATA[Subtitle: Product updates, field notes, and practical security for MSPs &#8212; without the vendor fluff.]]></description><link>https://press.dual-strike.com/p/welcome-to-the-dual-strike-dispatchhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/welcome-to-the-dual-strike-dispatchhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 01 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Product updates, field notes, and practical security for MSPs &#8212; without the vendor fluff.</p><div><hr></div><p>If you run an MSP, MSSP, or internal security team, you already have too many dashboards. What you rarely get is a straight answer to three questions:</p><ol><li><p><strong>What actually shipped?</strong></p></li><li><p><strong>Does it matter to my clients?</strong></p></li><li><p><strong>What do I do Monday morning?</strong></p></li></ol><p>That&#8217;s what this publication is for.</p><p><strong>Dual-Strike XISEM</strong> is our security intelligence and policy platform: evidence from agents, browsers, identity, and integrations &#8212; correlated into posture, detections, compliance, and response. We build the <strong>agent</strong>, the <strong>Anti-Venom Secure Access</strong> browser extension, and the <strong>console</strong> on one version line so your fleet doesn&#8217;t drift.</p><p>Here&#8217;s what you&#8217;ll see here:</p><ul><li><p><strong>Release notes</strong> you can forward to clients (8.7.x, extension store updates, platform UI)</p></li><li><p><strong>Capability deep-dives</strong> (Managed Identity Provider, Browsing Insights, PSA ticketing)</p></li><li><p><strong>Integration announcements</strong> (RMM/PSA, EDR, identity infeeds)</p></li><li><p><strong>Occasional essays</strong> on why tool sprawl fails &#8212; and what &#8220;working together&#8221; actually looks like</p></li></ul><p>We won&#8217;t publish internal runbooks, infrastructure gossip, or &#8220;we fixed a query.&#8221; We will publish what changes <strong>your</strong> operational reality.</p><p><strong>Get started:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; <a href="https://dual-strike.com/downloads">Downloads</a> &#183; <a href="https://dual-strike.com/demo">Request a demo</a></p><p>Subscribe so you don&#8217;t have to watch GitHub.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Welcome to the Dual-Strike Dispatch]]></title><description><![CDATA[Subtitle: Product updates, field notes, and practical security for MSPs &#8212; without the vendor fluff.]]></description><link>https://press.dual-strike.com/p/feedxml</link><guid isPermaLink="false">https://press.dual-strike.com/p/feedxml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 01 Jun 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Product updates, field notes, and practical security for MSPs &#8212; without the vendor fluff.</p><div><hr></div><p>If you run an MSP, MSSP, or internal security team, you already have too many dashboards. What you rarely get is a straight answer to three questions:</p><ol><li><p><strong>What actually shipped?</strong></p></li><li><p><strong>Does it matter to my clients?</strong></p></li><li><p><strong>What do I do Monday morning?</strong></p></li></ol><p>That&#8217;s what this publication is for.</p><p><strong>Dual-Strike XISEM</strong> is our security intelligence and policy platform: evidence from agents, browsers, identity, and integrations &#8212; correlated into posture, detections, compliance, and response. We build the <strong>agent</strong>, the <strong>Anti-Venom Secure Access</strong> browser extension, and the <strong>console</strong> on one version line so your fleet doesn&#8217;t drift.</p><p>Here&#8217;s what you&#8217;ll see here:</p><ul><li><p><strong>Release notes</strong> you can forward to clients (8.7.x, extension store updates, platform UI)</p></li><li><p><strong>Capability deep-dives</strong> (Managed Identity Provider, Browsing Insights, PSA ticketing)</p></li><li><p><strong>Integration announcements</strong> (RMM/PSA, EDR, identity infeeds)</p></li><li><p><strong>Occasional essays</strong> on why tool sprawl fails &#8212; and what &#8220;working together&#8221; actually looks like</p></li></ul><p>We won&#8217;t publish internal runbooks, infrastructure gossip, or &#8220;we fixed a query.&#8221; We will publish what changes <strong>your</strong> operational reality.</p><p><strong>Get started:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; <a href="https://dual-strike.com/downloads">Downloads</a> &#183; <a href="https://dual-strike.com/demo">Request a demo</a></p><p>Subscribe so you don&#8217;t have to watch GitHub.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item></channel></rss>