SOC
Latest
Practice at Home the Way You Preach at Work
I spend my working hours telling teams how to do security well. Segment the network. Write the change down. Model the threat before you build the control. Then I go home, and if I am honest with myself, the temptation is to cut every one of those corners because it is "just the lab."
From Log to Incident, and the Budget That Decides What You See
I have taught this material before as two sessions, and I usually open each session the same way: this is not a tool class. Tools get named below, plenty of them, but every one is an implementation of the same pipeline, and the pipeline is what transfers to whatever product your employer bought...
Every Seat in the SOC: The Incident Response and Investigation Labs in the Cybersecurity Architect's Handbook, Second Edition
This installment does something different. Every domain we've covered so far — even the unglamorous hygiene loop — was, at bottom, an attempt to keep the bad day from arriving. This one starts the morning after it did...
Ship Detections That Actually Work: A Hands-On Workshop for SOC Teams
If you've ever sat through a cybersecurity talk and thought, "Great framework, but how do I actually use this tomorrow?" — you're not alone. That frustration is exactly why Packt Publishing is sponsoring Powering Your SOC Team with AI Workshop: Real Incidents, Real Lessons exists.