Articles

技术文章

All SOC Notes Detection Engineering AI Agent Cloud Security Forensics Automation

Building an Effective SOC Playbook from Scratch

A practical guide to designing SOC playbooks that balance automation with human judgment, covering alert triage workflows, escalation procedures, and metrics that matter.

Read More

Microsoft Sentinel Detection Engineering: A Practical Approach

How to build detection-as-code workflows with Microsoft Sentinel, covering KQL rule authoring, version control, testing pipelines, and continuous tuning strategies.

Read More

AI Agents in Security Operations: Current State and Future

Exploring how autonomous AI agents can augment SOC analysts — from alert summarization to automated investigation and response orchestration.

Read More

AWS CloudTrail Threat Detection with Sigma Rules

Translating cloud-native audit logs into Sigma detection rules for portable, vendor-agnostic threat detection across AWS environments.

Read More

Memory Forensics with Volatility 3: Investigating Fileless Malware

A hands-on walkthrough of using Volatility 3 for memory forensics, focusing on detecting fileless malware techniques and extracting forensic artifacts.

Read More

SOAR Integration Patterns for Modern Security Teams

Design patterns for integrating SOAR platforms with existing security tooling, covering API orchestration, data normalization, and scalable automation architectures.

Read More