visitor@thefish.nz:~$ grep -r field-guide
#field-guide
all
account-compromise
analyst-methodology
authentication
beginner
betrayal
blue-team
career
cis-controls
cloud-security
control-mapping
control-testing
ctf
dark-waters
dark-web
detection
detection-engineering
dfir
dkim
dmarc
email-security
entra-id
field-guide
google-dorking
governance
http-server
identity
incident-response
interview
investigation
iso-27001
kase-scenarios
kql
lolbins
microsoft-365
networking
nist-csf
nzism
orkla
osi-model
osint
penetration-testing
phishing
physical-security
powershell
proxmark3
qilin
ransomware
research
rfid
risk-management
risk-reporting
scoping
security-assurance
security-frameworks
security-metrics
siem
skills
soc
soc-2
social-media
socmint
spf
spiderfoot
splunk
supplier-assurance
third-party-risk
threat-actors
threat-hunting
tools
trace-labs
try-hack-me
verification
vulnerability-management
windows
windows-event-logs
- CIS, NIST, ISO 27001 and NZISM: The Interview Guide for Security Practitioners
- Related Is Not Identical: Framework and Control Mapping Without the Spreadsheet Monster
- Lead With the Decision: Executive Security Risk Reporting
- Which Part? Cloud and SaaS Security Assurance
- Not the Assessment Itself: How to Design a Supplier Security Questionnaire
- Read the Scope Before the Findings: How to Review a Penetration Test Report
- Count Is Not Risk: Security Metrics, KPIs and KRIs That Actually Matter
- A Clean Opinion Is Not Zero Risk: How to Read a SOC 2 Report
- Present Is Not Effective: How to Test Security Controls
- Inherent Risk Comes First: Supplier Security Assurance for Analysts
- A Claim Is Not Evidence: Security Assurance for SOC Analysts
- Same Problem, Four Lenses: CIS vs NIST vs ISO 27001 vs NZISM
- Search It, Don't Memorise It: NZISM for Security Practitioners
- Check the Scope First: ISO 27001 for SOC Analysts
- Six Functions, Not Six Steps: NIST CSF 2.0 for SOC Analysts
- Beyond the Alert: CIS Critical Security Controls v8.1 for SOC Analysts
- One Alert Is Not the Incident: Scoping Security Incidents in the SOC
- Windows Event Logs for SOC Analysts: What an Event ID Actually Proves
- Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis
- SPF, DKIM and DMARC: What They Actually Prove (and What They Don't)
- Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts
- PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity
- The IP Isn't the Attacker: A SOC Analyst's Guide to NAT, VPNs and Proxies
- Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise
- How to Think Like a SOC Analyst in an Interview
- From Header to Host: Investigating Phishing in the SOC
- Alert to Conclusion: Investigating Without Tunnel Vision
- OSINT Corroboration: How Do I Know I've Found the Right Person?
- Social Media OSINT: From One Profile to a Digital Footprint
- Google Dorking for Trace Labs: 50 OSINT Investigation Pivots
- Google Dorking for OSINT: The Practical Investigator's Guide