visitor@thefish.nz:~$ grep -r incident-response
#incident-response
all
account-compromise
analyst-methodology
authentication
beginner
betrayal
blue-team
career
ctf
dark-waters
dark-web
detection
detection-engineering
dfir
dkim
dmarc
email-security
entra-id
field-guide
google-dorking
http-server
identity
incident-response
interview
investigation
kase-scenarios
kql
lolbins
microsoft-365
networking
orkla
osi-model
osint
phishing
physical-security
powershell
proxmark3
qilin
ransomware
research
rfid
scoping
siem
skills
soc
social-media
socmint
spf
spiderfoot
splunk
threat-actors
threat-hunting
tools
trace-labs
try-hack-me
verification
windows
windows-event-logs
- One Alert Is Not the Incident: Scoping Security Incidents in the SOC
- Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts
- Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise
- How to Think Like a SOC Analyst in an Interview
- From Header to Host: Investigating Phishing in the SOC