Tutorials
Step-by-step tutorials for SOC analysts: log analysis, KQL and Sigma, SIEM and XDR investigation, and hands-on alert triage you can practice on SOCSimulator.

NTLM vs Kerberos: Differences and How to Read Them in Logs
NTLM vs Kerberos side by side, the 4624, 4776 and 4769 fields that show which one ran, why Windows falls back, and SPL and KQL that catch a downgrade.

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage
The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Windows Logon Types: A Triage Guide for Every 4624 Value
Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Device Code Phishing: How OAuth Token Theft Bypasses MFA (and How to Detect It)
Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.

Redline Stealer Analysis: How Infostealers Work and How to Detect Them
Redline Stealer is a malware-as-a-service infostealer that steals credentials, tokens, clipboard data, and screenshots. Learn to detect and triage it.

Kusto Query Language (KQL): A SOC Analyst's Practical Tutorial
Kusto Query Language (KQL) is how you query Microsoft Sentinel and Defender XDR logs. Learn to read a KQL query, write one, and run two real triage examples.

Sigma Rules Explained: Read, Write, and Convert One
Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

MITRE ATT&CK for SOC Analysts: Tactics, IDs, Examples
All 15 Enterprise tactic IDs (Lateral Movement is TA0008), how techniques nest under them, and a worked alert chain mapped to ATT&CK step by step.