Forem

# blueteam

Defensive security strategies, threat detection, and incident response.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How I taught a log scanner to tell brute force from credential spray

How I taught a log scanner to tell brute force from credential spray

Comments
4 min read
After event viewer crashed on a 400mb evtx, i wrote my own log triage cli

After event viewer crashed on a 400mb evtx, i wrote my own log triage cli

Comments
4 min read
Pick offense or defense

Pick offense or defense

Comments
6 min read
Why SOC analysts get inconsistent results from ChatGPT (and how structured workflows fix it)

Why SOC analysts get inconsistent results from ChatGPT (and how structured workflows fix it)

Comments
2 min read
Sysmon Logs Deep-Dive - From Raw Data to Threat Evidence

Sysmon Logs Deep-Dive - From Raw Data to Threat Evidence

3
Comments
6 min read
I Built a Honeypot That Profiles Attackers and Maps Their Behavior to MITRE ATT&CK

I Built a Honeypot That Profiles Attackers and Maps Their Behavior to MITRE ATT&CK

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.