Explore by vertical
blue-team practice areasSOC Operations
Running the SOC — triage, shift workflow, metrics, and the automation that keeps queues moving.
Incident Response
Running the response when it matters — investigation, containment, and the writeups that make the next one faster.
Identity Security
Tokens, Conditional Access, and proving who is really signing in.
Endpoint Security
Defending the device — detections, remediation, and the hardening that shrinks the attack surface.
Email Security
Mail flow, deliverability, and the phishing war in both directions.
Detection Engineering
Turning telemetry into signal — advanced hunting, analytics rules, and cutting the noise.
Cloud Security
Securing the cloud estate — secure service edge, posture, and config hardening across Azure and AWS.
Digital Forensics
Preservation and discovery — litigation holds, eDiscovery, and the incidents holds cause.