Skip to main content
Back to all posts
Tag

#blue-team

Silhouetted figures standing inside a dark immersive installation with cascading blue-white data lights falling like rain around them
Tutorials

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)

SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Dark analytics dashboard on a tablet screen displaying colorful performance charts and session metrics against a black background
Best Practices

Best SIEM Tools in 2026: 12 Platforms Ranked

12 best SIEM tools for 2026, re-checked in September: Splunk under Cisco, QRadar SaaS moved to Cortex XSIAM, pricing models, and who each one fits.

MacBook Pro on a dark desk with a colorful code editor open showing syntax-highlighted source code in a dark theme
Best Practices

Open Source SIEM: 7 Free Tools for Your Home Lab (2026)

Open source SIEM tools to self-host on Linux with Docker: Wazuh, OpenSearch and 5 more, with RAM specs and which licenses are truly open source.

Hand holding a blue pen writing notes on paper at a wooden desk with a coffee mug and notebook beside it
Best Practices

Best Cybersecurity Certifications for Beginners: 2026 Costs

8 beginner certs ranked for SOC analyst jobs, with prices checked on each issuer's site in Sept 2026: Security+ $439, BTL1 £399, ISC2 CC no longer free.

Windows Security event log entries displayed in a SIEM console, showing event IDs for authentication and process activity
Tutorials

Windows Event IDs & Codes Cheat Sheet: The 31 That Matter

The 31 Windows event IDs and codes SOC analysts triage most: logon, Kerberos, process, services, Sysmon, log clearing, plus detection pages for 12 of them.

Network traffic analysis dashboard showing TCP and UDP port connections, firewall logs, and protocol distribution for SOC triage
Tutorials

Common Port Numbers Cheat Sheet: 42 Ports for SOC Triage

The 42 TCP/UDP port numbers SOC analysts read in firewall logs and SIEM alerts, what each one means in triage, and a printable cheat sheet image to save.

Wax-sealed envelope beside a magnifying glass on a dark surface with a glowing phishing hook and orange code overlay in the background
Tutorials

How to Analyze a Phishing Email: SOC Walkthrough

A step-by-step SOC workflow to analyze a phishing email: safe handling, header forensics, URL and attachment triage, and a documented verdict.

Close-up of a dark SIEM dashboard on a widescreen monitor, rows of alerts highlighted in orange, gloved hands at the keyboard
Tutorials

Alert Triage: Real Threats vs False Positives

Alert triage is the core SOC skill. Learn the framework analysts use to assess severity, confirm IOCs, and separate real threats from false positives.

Two silhouettes facing each other across a table with a large curved orange-lit world map and data dashboard screen behind them
Best Practices

SOC Analyst Interview Questions: 30 With Answers

SOC analyst interview questions decoded: what interviewers test, sample answers, and log examples to study before your first security ops interview.