Insights & Updates

Technical deep dives, incident response stories, and practical guidance from the Command Centre IT cyber defence team.

Endpoint Security2026-02-16· 10 min read

Tuning fanotify to Crush the 15% MDE Bottleneck (and Stop RTP Storms for Good)

When real-time protection turns into an RTP storm, fanotify becomes the choke point. Here's how to surgically tune exclusions, architect mounts, and eliminate unnecessary permission events — without reducing meaningful coverage.

Read the full story

What you'll learn

  • How fanotify permission events create RTP storms under high I/O
  • Path exclusion strategies that drop CPU from 15% to under 8%
  • Mount architecture, OverlayFS tuning, and bottleneck measurement

Latest Articles

Curated insights on managed security, incident response, and cyber defence.

Endpoint Security2026-02-10· 8 min read

Linux Real-Time Protection Without the Fallout

Understanding the fanotify bottleneck, the 15% CPU myth, and why eBPF is not your enemy. A practical view of why Linux RTP stalls under real load and how to design flow-aware protection.

Linux RTP
Read more
Endpoint Security2026-02-09· 10 min read

MDE on Linux: Exclusions, fanotify, eBPF, and a Risk-Based Testing Framework

Defender for Endpoint on Linux is kernel-adjacent: fanotify for real-time decisions, eBPF for behavioural detections, and a multi-process wdavdaemon architecture. Here’s how we stress test it and govern exclusions without creating blind spots.

MDE Linux
Read more
Incident Response2024-10-12· 6 min read

How We Restored Critical Services After a DNS-Based Attack

When an energy provider’s external DNS was hijacked, customers lost access to key services. Here’s how we diagnosed, contained, and restored their communications in record time.

DNS Security
Read more
Managed Security2024-09-03· 8 min read

What a Modern SOC Really Looks Like in 2025

From AI-driven detection to real-time attack disruption, this is how we design and run modern security operations for our clients.

Professional Services2024-07-21· 7 min read

Vulnerability Management That Actually Reduces Risk

Scanning alone doesn’t reduce risk. We walk through how we prioritise vulnerabilities, align with business impact, and drive real remediation.

Vulnerability Management
Read more
Training & Awareness2024-06-05· 5 min read

Security Awareness Training That People Don’t Hate

Most awareness training is forgettable. Here’s how we design sessions that staff remember—and attackers dislike.

Human Risk
Read more