Skip to main content
Back to all posts
Tag

#siem

Abstract dark illustration of three stacked translucent layers with a single amber line passing down through each one
Best Practices

SOC Tools by Tier: What T1, T2 and T3 Analysts Open First

SOC tools sorted by tier and task, not category: what a T1 analyst opens in an alert's first 10 minutes, what T2 and T3 add, and what to practice free.

Abstract dark illustration of numbered authentication paths converging on a single Windows security log entry
Tutorials

Windows Logon Types: A Triage Guide for Every 4624 Value

Every Windows logon type, what produces it in a healthy environment, what it means when it appears where it should not, and the queries to hunt it.

Abstract rows of dark ridged slats curving across a black background, lit by a warm orange glow, evoking parallel paths fanning out from one source
Tutorials

Sigma Rules Explained: Read, Write, and Convert One

Sigma rules are vendor-agnostic YAML detections. Read one rule field by field, then see its real sigma-cli output in Splunk SPL and Microsoft Sentinel KQL.

Abstract rows of dark glass slats receding diagonally with a warm orange glow, evoking scrolling log lines
Tutorials

How to Read Windows Event Logs: A SOC Analyst Guide

How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.

Green Matrix-style falling code characters cascading down a pure black background, representing data stream analysis and threat hunting
Best Practices

Cyber Threat Hunting Tools: 13 SOC Analysts Use (2026)

Cyber threat hunting tools every SOC analyst needs: Sigma, YARA, KQL, Velociraptor, Wireshark, Zeek, MISP and more, grouped by layer with code examples.

Silhouetted figures standing inside a dark immersive installation with cascading blue-white data lights falling like rain around them
Tutorials

SIEM Use Cases: 10 Every SOC Runs (With Detection Logic)

SIEM use cases explained with detection logic sketches, data sources, and tuning notes for the 10 detections every SOC team operates.

Dark analytics dashboard on a tablet screen displaying colorful performance charts and session metrics against a black background
Best Practices

Best SIEM Tools in 2026: 12 Platforms Ranked

12 best SIEM tools for 2026, re-checked in September: Splunk under Cisco, QRadar SaaS moved to Cortex XSIAM, pricing models, and who each one fits.

MacBook Pro on a dark desk with a colorful code editor open showing syntax-highlighted source code in a dark theme
Best Practices

Open Source SIEM: 7 Free Tools for Your Home Lab (2026)

Open source SIEM tools to self-host on Linux with Docker: Wazuh, OpenSearch and 5 more, with RAM specs and which licenses are truly open source.

Windows Security event log entries displayed in a SIEM console, showing event IDs for authentication and process activity
Tutorials

Windows Event IDs & Codes Cheat Sheet: The 31 That Matter

The 31 Windows event IDs and codes SOC analysts triage most: logon, Kerberos, process, services, Sysmon, log clearing, plus detection pages for 12 of them.