Active Directory Security Monitoring: Detection Queries for DCSync, Kerberoasting, and Privilege Escalation

Production detection queries for the AD attack techniques that appear in almost every enterprise breach — DCSync, Kerberoasting, pass-the-hash, privilege escalation, and LDAP enumeration.

Credential Dumping Detection: How to Catch LSASS Access, Mimikatz, and Hash Theft

Production detection queries for credential dumping — LSASS memory access, Mimikatz command line patterns, SAM database access, NTDS.dit extraction, and ProcDump targeting LSASS.

SOC Runbook Template: How to Write IR Runbooks That Work Under Pressure

What separates runbooks that get used at 3AM from the ones that sit in SharePoint untouched. Complete template structure, the most common mistakes, and the 2AM test every runbook must pass.

Entra ID Detection with KQL: Microsoft Sentinel Queries for Cloud Identity Attacks

Production KQL queries for detecting Entra ID attacks — AiTM token replay, impossible travel, privileged role changes, suspicious OAuth consent, guest account abuse, and risky sign-ins.

Alert Triage Automation with SOAR: What to Automate, What Not To, and How to Start

The automation readiness test, what works well for SOAR automation, what doesn't, and how to build the first automation that actually reduces analyst workload instead of adding to it.

Kerberoasting Detection: How to Find It Before the Password Gets Cracked

How to detect Kerberoasting during the ticket request phase — before offline cracking begins. RC4 ticket detection, SPN enumeration, and lateral movement correlation across Sentinel, Splunk, and CrowdStrike.

Threat Hunting Process: A Repeatable Framework SOC Analysts Actually Use

Hypothesis generation, hunt execution, evidence documentation, and detection engineering output. With working queries for CrowdStrike, Sentinel, and Splunk you can run today.

KQL Detection Engineering: Writing Sentinel Rules That Actually Fire Correctly

Production KQL patterns for Sentinel — allowlist suppression, dynamic baselining, multi-signal correlation, entity mapping, and a tuning workflow that works before rules go live.

Splunk SOC Queries: Production SPL for Triage, Hunting, and Incident Response

Five production SPL queries covering suspicious process creation, brute force detection, NTLM lateral movement, data exfiltration volume, and scheduled task persistence — with tuning notes.

MITRE ATT&CK Detection Coverage: How to Map Your Rules and Find Real Gaps

How to map your detection rules to MITRE ATT&CK, measure coverage honestly across three confidence levels, and prioritize what to build next based on your actual threat profile.

SOC Metrics That Actually Matter: What to Measure and How to Report to Leadership

MTTD, MTTR, false positive rate, and detection coverage — what each means, how to calculate it honestly, and how to translate it into business risk language for non-technical leadership.

Windows Event ID 4688 and Critical Security Event IDs Every SOC Analyst Must Monitor

What Event ID 4688 actually tells you and which Windows Security Event IDs matter most. Production detection queries for Sentinel, Splunk, and CrowdStrike with command line logging setup.

Insider Threat Detection: Queries and Behavioral Indicators for SOC Teams

Behavioral analytics and SIEM queries for detecting insider threats. Data volume anomalies, USB usage, after-hours access, email forwarding rules, and print volume detection.

CrowdStrike Falcon Detection Rules: Production LogScale Queries for SOC Teams

Seven production LogScale detection rules covering PowerShell from Office apps, LOLBin abuse, reflective DLL injection, DNS correlation, service installation, and mass file deletion.

Splunk Threat Hunting Queries: Production SPL for SOC Analysts

Seven production Splunk SPL queries covering LOLBin detection, encoded PowerShell, admin account creation, credential dumping, scheduled task persistence, lateral movement, and recon.

Ransomware Incident Response: The SOC Checklist Built From Real Incidents, Not Vendor Docs

A step-by-step ransomware IR checklist from real incidents at major financial institutions. Isolation steps, evidence preservation, containment sequence, and communication scripts.

Lateral Movement Detection: Production Queries for CrowdStrike, Sentinel, and Splunk

How to detect lateral movement using behavioral anomaly detection. First-time host authentication, SMB volume anomalies, WMI execution, and pass-the-hash patterns with production queries.

Microsoft Sentinel KQL Queries for Threat Hunting: Production-Ready Detections

Six production-tested KQL queries for Sentinel covering suspicious PowerShell, new admin accounts, impossible travel, scheduled task creation, mass file access, and MFA bypass detection.

CrowdStrike LogScale Queries Every SOC Analyst Should Know

Five production-tested LogScale queries for detecting LOLBin abuse, suspicious PowerShell, off-hours admin account creation, mass file deletion, and BloodHound LDAP reconnaissance.

How to Detect PowerShell Encoded Commands in Microsoft Sentinel

A working SOC analyst's guide to detecting PowerShell -EncodedCommand abuse using a weighted scoring model, with MITRE ATT&CK mapping and real-world tuning notes.

SOC Analyst Interview Questions and Answers: What Hiring Managers Actually Ask

Real SOC analyst interview questions with detailed answers. Technical investigation questions, scenario-based questions, and what experienced hiring managers are actually evaluating.

Phishing Incident Response: A Step-by-Step Runbook for SOC Teams

Complete phishing IR runbook covering detection, containment, investigation, communication scripts, and recovery. Built from real phishing incidents at major financial institutions.

SOC Alert Triage Process: The 5-Phase Method That Works at 2AM

A repeatable 5-phase alert triage process covering severity assessment, context building, investigation, escalation, and documentation. Includes a P1 to P4 severity matrix.

Founding member pricing — locked for life
Get a new detection rule every Tuesday

Production detection rule, real incident case study, hunt hypothesis, and career tip — every Tuesday. Plus monthly Office Hours and a private Discord. $14.99/month, founding member rate locked for life.

Join the Intelligence Pack — $14.99/mo →