Investigation notes
Security Notes
Practical writing on SOC investigations, telemetry, detection validation, cloud identity, and CTI-to-detection workflows.
From IOC to Detection Use Case: How CTI Becomes SOC Work
Currently BuildingA sanitized concept article on transforming threat intelligence into SOC-ready work through normalization, ATT&CK mapping, telemetry checks, detection templates, and analyst handoffs.
Read security noteCTIMISPMITRE ATT&CK+2July 22, 20262 min readOAuth and Service Principal Risk in Entra ID: What SOC Analysts Should Watch
Why OAuth applications, service principals, app credentials, owners, consent activity, and privileged app roles matter in cloud-security investigations.
Read security noteEntra IDOAuthService Principals+2July 21, 20262 min readSigma Rules Are Not Enough: Why Detection Validation Matters
Why detection logic must be supported by telemetry requirements, parsing checks, false-positive analysis, validation evidence, and analyst handoff notes.
Read security noteDetection EngineeringSigmaValidation+2July 20, 20262 min readInvestigating Suspicious PowerShell: A SOC Analyst Evidence Chain
A lab-based walkthrough from alert to structured investigation using process context, command-line evidence, network indicators, ATT&CK mapping, and reporting.
Read security noteSOC InvestigationPowerShellWindows Logs+2July 19, 20262 min readBuilding a Home SOC Lab with Wazuh and Sysmon
A practical explanation of how a controlled SOC lab can collect Windows endpoint telemetry, support alert investigation, validate detections, and document analyst workflows.
Read security noteSOC LabWazuhSysmon+2July 18, 20262 min read