Back to all postsTag 

#mitre-attack
2 articles

Tutorials
Sigma Rules Explained: A SOC Analyst's Reading Guide
Sigma rules are a vendor-agnostic YAML format for writing one SIEM detection that runs anywhere. Learn to read one, write one, and map it to MITRE ATT&CK.

Tutorials
MITRE ATT&CK Explained: A SOC Analyst's Field Guide
What MITRE ATT&CK actually is, how tactics and techniques work together, and how tier-1 analysts use the framework to triage alerts and find gaps.