visitor@thefish.nz:~$ posts
Posts
Click a topic or start typing to follow the connections between posts.
Commands (optional — typing a tag name works too)
add <tag>- select a tag
remove <tag>- deselect a tag
clear- deselect everything
reset- return the explorer to its initial state
mode and|or- switch match mode
posts on|off- toggle article nodes in the graph
focus <tag>- select and expand a tag
random- jump into a random topic
help- show this list
node size = posts line = shared posts
all
account-compromise
analyst-methodology
authentication
beginner
betrayal
blue-team
career
cis-controls
cloud-security
control-mapping
control-testing
ctf
dark-waters
dark-web
detection
detection-engineering
dfir
dkim
dmarc
email-security
entra-id
field-guide
google-dorking
governance
http-server
identity
incident-response
interview
investigation
iso-27001
kase-scenarios
kql
lolbins
microsoft-365
networking
nist-csf
nzism
orkla
osi-model
osint
penetration-testing
phishing
physical-security
powershell
proxmark3
qilin
ransomware
research
rfid
risk-management
risk-reporting
scoping
security-assurance
security-frameworks
security-metrics
siem
skills
soc
soc-2
social-media
socmint
spf
spiderfoot
splunk
supplier-assurance
third-party-risk
threat-actors
threat-hunting
tools
trace-labs
try-hack-me
verification
vulnerability-management
windows
windows-event-logs
43 posts
- CIS, NIST, ISO 27001 and NZISM: The Interview Guide for Security Practitioners
- Related Is Not Identical: Framework and Control Mapping Without the Spreadsheet Monster
- Lead With the Decision: Executive Security Risk Reporting
- Which Part? Cloud and SaaS Security Assurance
- Not the Assessment Itself: How to Design a Supplier Security Questionnaire
- Read the Scope Before the Findings: How to Review a Penetration Test Report
- Count Is Not Risk: Security Metrics, KPIs and KRIs That Actually Matter
- A Clean Opinion Is Not Zero Risk: How to Read a SOC 2 Report
- Present Is Not Effective: How to Test Security Controls
- Inherent Risk Comes First: Supplier Security Assurance for Analysts
- A Claim Is Not Evidence: Security Assurance for SOC Analysts
- Same Problem, Four Lenses: CIS vs NIST vs ISO 27001 vs NZISM
- Search It, Don't Memorise It: NZISM for Security Practitioners
- Check the Scope First: ISO 27001 for SOC Analysts
- Six Functions, Not Six Steps: NIST CSF 2.0 for SOC Analysts
- Beyond the Alert: CIS Critical Security Controls v8.1 for SOC Analysts
- One Alert Is Not the Incident: Scoping Security Incidents in the SOC
- Windows Event Logs for SOC Analysts: What an Event ID Actually Proves
- Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis
- SPF, DKIM and DMARC: What They Actually Prove (and What They Don't)
- Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts
- PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity
- The IP Isn't the Attacker: A SOC Analyst's Guide to NAT, VPNs and Proxies
- Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise
- How to Think Like a SOC Analyst in an Interview
- From Header to Host: Investigating Phishing in the SOC
- Alert to Conclusion: Investigating Without Tunnel Vision
- OSINT Corroboration: How Do I Know I've Found the Right Person?
- Social Media OSINT: From One Profile to a Digital Footprint
- Google Dorking for Trace Labs: 50 OSINT Investigation Pivots
- Google Dorking for OSINT: The Practical Investigator's Guide
- Trace Labs OSINT Search Party CTF 2026 (DEF CON 34)
- ProxLab: A Friendlier Front End for the Proxmark3
- Kase Scenarios - Orkla: Dragon Con Detective
- Kase Scenarios - Orkla: Bounty Hunt
- Kase Scenarios - Betrayal
- The Insider Threat CTF (1)
- Spiderfoot
- KaffeeSec - SoMeSINT
- Kase Scenarios - Dark Waters
- Simple HTTP Server
- A Beginners Guide to the Dark Web
- A Simplified Explanation of the OSI 7 Layer System