visitor@thefish.nz:~$ grep -r investigation
#investigation
all
account-compromise
analyst-methodology
authentication
beginner
betrayal
blue-team
career
cis-controls
cloud-security
control-mapping
control-testing
ctf
dark-waters
dark-web
detection
detection-engineering
dfir
dkim
dmarc
email-security
entra-id
field-guide
google-dorking
governance
http-server
identity
incident-response
interview
investigation
iso-27001
kase-scenarios
kql
lolbins
microsoft-365
networking
nist-csf
nzism
orkla
osi-model
osint
penetration-testing
phishing
physical-security
powershell
proxmark3
qilin
ransomware
research
rfid
risk-management
risk-reporting
scoping
security-assurance
security-frameworks
security-metrics
siem
skills
soc
soc-2
social-media
socmint
spf
spiderfoot
splunk
supplier-assurance
third-party-risk
threat-actors
threat-hunting
tools
trace-labs
try-hack-me
verification
vulnerability-management
windows
windows-event-logs
- One Alert Is Not the Incident: Scoping Security Incidents in the SOC
- Windows Event Logs for SOC Analysts: What an Event ID Actually Proves
- Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis
- Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts
- PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity
- Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise
- How to Think Like a SOC Analyst in an Interview
- From Header to Host: Investigating Phishing in the SOC
- Alert to Conclusion: Investigating Without Tunnel Vision
- OSINT Corroboration: How Do I Know I've Found the Right Person?
- Social Media OSINT: From One Profile to a Digital Footprint
- Google Dorking for Trace Labs: 50 OSINT Investigation Pivots