Paths by topic
For each area, everything together: the tools to use, the labs to practice and the articles to read. Pick a topic and follow the thread.
Phishing & email
From a suspicious email to a verdict: analyze headers, authenticate the domain and dissect the trick.
Detection Engineering
From a real log to the rule that catches the attack: write Sigma/YARA, measure it and hunt in a mini-SIEM.
- Use Sigma Forge
- Use Detection Linter
- Use CVE to Detection
- Use YARA rule generator
- Practice Threat Hunting Lab (mini-SIEM)
- Read From a log to a detection that works in any SIEM
- Read From a CVE to a detection: from the advisory to a rule that catches the attack
- Read The Windows Event IDs every SOC should watch
Vulnerabilities & Threat Intel
What's exploited now, how it's scored and what to patch first.
Fundamentals: "how it works"
The internals an analyst takes for granted, step by step and interactive.