Your First SOC Investigation in Splunk: Find the Logs, Then Follow the Alert
New to Splunk in a SOC? Learn where to search, how to find indexes and log types, read your first event, and investigate a realistic failed-login alert with simple SPL.
SOC CASE FILES
Practical security operations playbooks, threat investigations, and lessons from the field.
Latest investigation Your First SOC Investigation in Splunk: Find the Logs, Then Follow the AlertFIELD NOTES
15 investigations, playbooks, and engineering guides.
New to Splunk in a SOC? Learn where to search, how to find indexes and log types, read your first event, and investigate a realistic failed-login alert with simple SPL.
A hands-on guide for SOC analysts on how to investigate a hacked or defaced WordPress site. Learn how to scope the compromise, contain without destroying evidence, read Apache and PHP logs, tell a dropped webshell apart from live AJAX abuse, and harden the site so it doesn't happen again.
A hands-on guide for SOC analysts on how to investigate WAF login attacks in real-world environments. Learn how to triage alerts, identify attack patterns, reduce false positives, and make confident response decisions.
Discover how AI in the SOC is transforming alert triage, threat detection, and incident response. Learn from a SOC analyst’s first-hand experience with automation, real-world challenges, and 7 actionable steps for AI-powered security operations.
Walk through a realistic Qilin ransomware breach mapped to MITRE ATT&CK, review campaign indicators collected for this article, and apply a seven-step hardening checklist.
Learn how to set up a basic Cyber Threat Intelligence (CTI) program for your business, regardless of its size. This guide covers the essentials, from understanding CTI to choosing the right tools and getting your team on board.
I used to think healing led me into cybersecurity. It was the other way around. A story about Complex PTSD, a lupus diagnosis I ignored, a failed exam, and the ransomware incident where the thing I learned as a lonely kid finally became useful.
A comprehensive guide to understanding Google's new email sender requirements for 2024, with a focus on implementing DKIM to enhance email security and reduce spam.
This blog post explores a groundbreaking discovery by Shmuel Cohen at SafeBreach Labs, where Palo Alto Networks' Cortex XDR, a leading EDR platform, was turned into a tool for attackers. Dive into the technical details of the exploit and its implications for cybersecurity.
An in-depth analysis of the recent XZ Backdoor incident, highlighting the resilience of the open source community in the face of a sophisticated supply chain attack. This post unpacks the details of the CVE-2024-3094 event, where a well-executed backdoor nearly compromised major Linux distributions, and the collaborative effort that led to its discovery and mitigation.
Unlock the full potential of your home network with Pi-hole, the open-source software that blocks ads, trackers, and malware domains on all your devices. This guide walks you through the simple steps of installing Pi-hole using Docker, ensuring a secure, ad-free internet experience without the hassle.
Discover the power of UniversalWebTracker, a Python-based script designed for effortless website monitoring. Whether you're tracking updates or changes, this tool keeps you informed with precision and ease.
Hey there! Ever wondered how a simple blog turns into a tech adventure? That's what happened to me. This is a story about taking my blog from a basic setup to something way cooler with CI/CD, using Azure and GitHub.
Dive into the fascinating world of penetration testing with my latest adventure on Hack The Box's "Analytics" challenge. From initial reconnaissance to successful system exploitation, explore the intricate steps of a cyber sleuth.
Explore essential steps to harden your SSH port and prevent unauthorized access in this concise guide. Learn key security measures to protect your systems effectively.
No case files match this filter.