Security Insights
Research, tutorials, and analysis to help you become a more effective security analyst.

What Does a SOC Analyst Do? The Role, Explained by Tier
What does a SOC analyst do? A tier-by-tier breakdown of the role, a realistic daily shift, tools, skills, and common myths — for career switchers.
Latest Articles

NTLM vs Kerberos: How to Tell Which One Your Logs Are Showing You
NTLM vs Kerberos for SOC analysts: the 4624, 4776 and 4769 fields that name the protocol, why Windows falls back to NTLM, and queries that catch a downgrade.

Writing a SOC Playbook an Analyst Will Follow at 3 a.m.
What separates a SOC playbook analysts follow from a document that rots in a wiki: every step names a tool and a query, every branch carries a threshold.

Web Shell Detection: How to Find One, and Why Most Rules Miss It
Triage and detection logic for web shells: the process-parent rule, its real false positives, IIS log tells, and an ordered first 30 minutes.

Windows Logon Types: A Triage Guide for Every 4624 Value
Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Device Code Phishing: How OAuth Token Theft Bypasses MFA (and How to Detect It)
Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.

Redline Stealer Analysis: How Infostealers Work and How to Detect Them
Redline Stealer is a malware-as-a-service infostealer that steals credentials, tokens, clipboard data, and screenshots. Learn to detect and triage it.

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial
Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Sigma Rules Explained: A SOC Analyst's Reading Guide
Sigma rules are a vendor-agnostic YAML format for writing one SIEM detection that runs anywhere. Learn to read one, write one, and map it to MITRE ATT&CK.

How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.