Tools
Sigma, YARA, and Hunt helpers
Draft starting points for detection logic, then tune in your environment.
Topic
Use this topic for SOC requests, hunts, detection drafts, response actions, escalation, and action tracking.
Tools
Draft starting points for detection logic, then tune in your environment.
Playbook
Send specific telemetry, hunt, IOC, and monitoring requests with caveats.
Playbook
Keep owners, state, notes, and review dates attached to response work.
Guide
Understand whether telemetry and ownership can support a detection request.
Practice
Practice sorting clues into exploitation, exposure, remediation, trust, and business context.