Back to all postsTag 

#incident-response
2 articles

Best Practices
Writing a SOC Playbook an Analyst Will Follow at 3 a.m.
What separates a SOC playbook analysts follow from a document that rots in a wiki: every step names a tool and a query, every branch carries a threshold.

Tutorials
Web Shell Detection: How to Find One, and Why Most Rules Miss It
Triage and detection logic for web shells: the process-parent rule, its real false positives, IIS log tells, and an ordered first 30 minutes.