Classroom
Posts
Categories
Tags
Archives
Search
About
Home
Tags
Incident Response
SOC Level 2
Conti: ProxyShell to Ransomware in Splunk
SOC Level 2
Servidae: Tracing a Compromised Workstation in ELK
SOC Level 2
Response and Recovery: Containing an M365 Compromise From the Audit Log
SOC Level 2
Post-Incident Activity: Turning an Incident Into Detection Rules
SOC Level 2
Detection and Analysis: Scoping a Nexus Financial Account Compromise
SOC Level 2
SOC L2 Alert Triage: The Senior Workflow
SOC Level 2
Threat Intel & Containment: Buying Time on the Adversary
SOC Level 2
Identification & Scoping: Working a Phishing Incident
SOC Level 2
Preparation: The First Phase of Incident Response