visitor@thefish.nz:~$ grep -r soc
#soc
all
account-compromise
analyst-methodology
authentication
beginner
betrayal
blue-team
career
ctf
dark-waters
dark-web
detection
detection-engineering
dfir
dkim
dmarc
email-security
entra-id
field-guide
google-dorking
http-server
identity
incident-response
interview
investigation
kase-scenarios
kql
lolbins
microsoft-365
networking
orkla
osi-model
osint
phishing
physical-security
powershell
proxmark3
qilin
ransomware
research
rfid
scoping
siem
skills
soc
social-media
socmint
spf
spiderfoot
splunk
threat-actors
threat-hunting
tools
trace-labs
try-hack-me
verification
windows
windows-event-logs
- One Alert Is Not the Incident: Scoping Security Incidents in the SOC
- Windows Event Logs for SOC Analysts: What an Event ID Actually Proves
- Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis
- SPF, DKIM and DMARC: What They Actually Prove (and What They Don't)
- Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts
- PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity
- The IP Isn't the Attacker: A SOC Analyst's Guide to NAT, VPNs and Proxies
- Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise
- How to Think Like a SOC Analyst in an Interview
- From Header to Host: Investigating Phishing in the SOC
- Alert to Conclusion: Investigating Without Tunnel Vision