#dfir

Cyberpunk robot holding a skull like Hamlet.

To Detect or Not to Detect

Guidelines for evaluating effective SOC detections.

· 5min · Joe Lopes
To Detect or Not to Detect
Illustration of a green radar with AI symbols.

Towards Actionable Detection

Actionable detection for relevant and contextual alerts.

· 4min · Joe Lopes
Towards Actionable Detection
Practical Threat Detection Engineering book cover.

Practical Threat Detection Engineering

Review of Practical Threat Detection Engineering book.

· 5min · Joe Lopes
Practical Threat Detection Engineering
Illustration of a cyberpunk cooker octopus.

Improving SecOps Beyond Tuning Analytics

· 5min · Joe Lopes
Improving SecOps Beyond Tuning Analytics
Clifford Stoll, author of The Cuckoo's Egg.

The Cuckoo's Egg

A 1980s Infosec thriller with groundbreaking investigations.

· 6min · Joe Lopes
The Cuckoo's Egg
Illustration of a cyberpunk character thinking atop a building.

The Threat Detection Fundamental Dilemma

Exploring the precision vs. recall dilemma in threat detection.

· 8min · Joe Lopes
The Threat Detection Fundamental Dilemma
A compass with integrated circuit.

Testing The Logfile Navigator

Log analysis with lnav: challenges, insights, and tips.

· 6min · Joe Lopes
Testing The Logfile Navigator
Engineer planning a house.

Insights into Effective SIEM Deployment

Strategies and tips for successful SIEM deployment.

· 8min · Joe Lopes
Insights into Effective SIEM Deployment
Security Operations robots monitoring alerts.

Understanding Severity and Priority

Find the best settings for consistent detection alerts.

· 3min · Joe Lopes
Understanding Severity and Priority
Intelligence-Driven Incident Response book cover.

Intelligence-Driven Incident Response

How integrating CTI enhances Threat Detection and CSIRT.

· 4min · Joe Lopes
Intelligence-Driven Incident Response
Illustration of cyberpunk air defense drones.

Automating Incident Response

Tackling log centralization, SIEM, and IR automation.

· 9min · Joe Lopes
Automating Incident Response
Illustration of a cyberpunk chess game.

Friction Between Red Teams and Incident Response

Reducing friction in Red Team cybersecurity exercises.

· 7min · Joe Lopes
Friction Between Red Teams and Incident Response
Illustration of a global reputation system.

Query Security Services for IP Reputation

Query three security services for IP reputation in one script.

· 4min · Joe Lopes
Query Security Services for IP Reputation