Skip to main content
Back to all posts
Tag

#blue-team

Abstract dark illustration of three stacked translucent layers with a single amber line passing down through each one
Best Practices

SOC Tools by Tier: What T1, T2 and T3 Analysts Open First

SOC tools sorted by tier and task, not category: what a T1 analyst opens in an alert's first 10 minutes, what T2 and T3 add, and what to practice free.

Abstract dark diagram of many dim branching paths with one amber route traced unbroken from left to right
Best Practices

SOC Playbook Template: Steps, Queries and Thresholds

Copy this SOC playbook template: triggers, steps, SPL/KQL/Lucene queries and branch thresholds for one alert type, with two filled-in examples.

Abstract dark chart of web request volume where one isolated bar is highlighted and branches into a small process tree
Tutorials

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage

The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Abstract dark illustration of numbered authentication paths converging on a single Windows security log entry
Tutorials

Windows Logon Types: A Triage Guide for Every 4624 Value

Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Abstract rows of dark ridged slats curving across a black background, lit by a warm orange glow, evoking parallel paths fanning out from one source
Tutorials

Sigma Rules Explained: Read, Write, and Convert One

Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

Abstract rows of dark glass slats receding diagonally with a warm orange glow, evoking scrolling log lines
Tutorials

How to Read Windows Event Logs: A SOC Analyst Guide

How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

Person at a MacBook Pro with a messaging app open in a cafe, simultaneously scrolling on a smartphone, iced drink on the table
Tutorials

Phishing Email Examples: 15 Analyzed by a SOC Analyst

Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

Dual-monitor workstation in a dark room showing code on an iMac and a landscape wallpaper on a second display, lit by a desk lamp
Best Practices

Best EDR Tools in 2026: What Tier 1 Analysts Learn First

Best EDR tools for SOC analysts: CrowdStrike, Defender, SentinelOne, Cortex XDR and more, ranked by console learnability and job-market frequency.

Green Matrix-style falling code characters cascading down a pure black background, representing data stream analysis and threat hunting
Best Practices

Cyber Threat Hunting Tools: 13 SOC Analysts Use (2026)

Cyber threat hunting tools every SOC analyst needs: Sigma, YARA, KQL, Velociraptor, Wireshark, Zeek, MISP and more, grouped by layer with code examples.