#blue-team

SOC Tools by Tier: What T1, T2 and T3 Analysts Open First
SOC tools sorted by tier and task, not category: what a T1 analyst opens in an alert's first 10 minutes, what T2 and T3 add, and what to practice free.

SOC Playbook Template: Steps, Queries and Thresholds
Copy this SOC playbook template: triggers, steps, SPL/KQL/Lucene queries and branch thresholds for one alert type, with two filled-in examples.

Web Shell Detection: KQL, IIS Logs and a 30-Minute Triage
The process-parent rule that finds web shells, the false positive that gets it muted, IIS log tells in KQL and Splunk, and an ordered first 30 minutes.

Windows Logon Types: A Triage Guide for Every 4624 Value
Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Sigma Rules Explained: Read, Write, and Convert One
Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

Phishing Email Examples: 15 Analyzed by a SOC Analyst
Phishing email examples analyzed with real analyst eyes: red flags, header tells, and the patterns every security-aware person should recognize.

Best EDR Tools in 2026: What Tier 1 Analysts Learn First
Best EDR tools for SOC analysts: CrowdStrike, Defender, SentinelOne, Cortex XDR and more, ranked by console learnability and job-market frequency.

Cyber Threat Hunting Tools: 13 SOC Analysts Use (2026)
Cyber threat hunting tools every SOC analyst needs: Sigma, YARA, KQL, Velociraptor, Wireshark, Zeek, MISP and more, grouped by layer with code examples.