Articles
技术文章
Building an Effective SOC Playbook from Scratch
A practical guide to designing SOC playbooks that balance automation with human judgment, covering alert triage workflows, escalation procedures, and metrics that matter.
Read MoreMicrosoft Sentinel Detection Engineering: A Practical Approach
How to build detection-as-code workflows with Microsoft Sentinel, covering KQL rule authoring, version control, testing pipelines, and continuous tuning strategies.
Read MoreAI Agents in Security Operations: Current State and Future
Exploring how autonomous AI agents can augment SOC analysts — from alert summarization to automated investigation and response orchestration.
Read MoreAWS CloudTrail Threat Detection with Sigma Rules
Translating cloud-native audit logs into Sigma detection rules for portable, vendor-agnostic threat detection across AWS environments.
Read MoreMemory Forensics with Volatility 3: Investigating Fileless Malware
A hands-on walkthrough of using Volatility 3 for memory forensics, focusing on detecting fileless malware techniques and extracting forensic artifacts.
Read MoreSOAR Integration Patterns for Modern Security Teams
Design patterns for integrating SOAR platforms with existing security tooling, covering API orchestration, data normalization, and scalable automation architectures.
Read More