Detection queries, IR runbooks, and threat hunting playbooks built from real incidents at major Canadian financial institutions. Not adapted from vendor docs.
Used on real incidents · CrowdStrike · Splunk · Microsoft Sentinel
Vendor documentation is written to sell products. Certification courses are written to pass exams. Consultant blogs are written to generate leads. None of it is written by someone who worked a ransomware incident at a financial institution last Tuesday.
Production-tested SOC tools you buy once and keep forever. No subscription required.
The one-time kits give you the foundation. The Intelligence Pack keeps you current — a new detection rule, a real incident case study, a hunt hypothesis, and a career tip, every single week.
Every issue is built from something that actually happened. A real alert that fired. A real investigation that ran. A real attacker technique that showed up in a production environment.
Plus monthly Office Hours where you can ask questions directly, and a private Discord with working analysts.
This is one production detection rule from the archive, complete and unedited. Every Tuesday subscribers get a new one like it — required logs, false positives, tuning notes, investigation steps, MITRE mapping, and ticket wording included.
Written by a working SOC and threat hunting analyst with 10+ years across CrowdStrike, Splunk, Sentinel, and Defender. Examples sanitized for education.
// PowerShell from Office or browser — Critical #event_simpleName=ProcessRollup2 ImageFileName=/\/powershell\.exe$/i ParentBaseFileName IN ( "WINWORD.EXE", "OUTLOOK.EXE", "chrome.exe", "msedge.exe" ) | table @timestamp ComputerName UserName CommandLine | "sort" @timestamp desc // Rarely legitimate in enterprise. // Treat as high confidence, investigate immediately.
I downloaded the free SOC starter kit first just to see what kind of material this was. Honestly, it was better than I expected. The severity matrix and step-by-step triage flow are the kind of things I can actually use during a shift, not just read once and forget.
The best part was how everything connected together — the detection rule, the hunt query, and the case study were all based on a real SOC-style scenario. It helped me think through what to check, what logs matter, how to reduce false positives, and how to write up the ticket.
I found the blog first and liked that the posts were not generic cybersecurity content. The hunting queries, investigation steps, and walkthroughs are written in a way that makes sense for someone actually working alerts.
Senior cybersecurity analyst with 10+ years in SOC operations, incident response, and threat hunting at major Canadian financial institutions. Every query and runbook on this site has been used on a real incident in a production environment, not adapted from vendor documentation by a consultant who theorizes about security.
CISSP · CEH · SANS FOR508 · CrowdStrike · Splunk · Microsoft Sentinel · Defender
If you need something to use right now — triage process, runbooks, hunting playbook — start with one of the one-time kits. They're immediately usable and you keep them forever. If you want new detection rules and case studies every week plus Office Hours access, the Intelligence Pack is the right add-on. Many people use both.
CrowdStrike Falcon LogScale, Microsoft Sentinel KQL, and Splunk SPL. The one-time kits include examples across all three. The Intelligence Pack rotates weekly so over a month you get coverage across all three platforms.
Yes. 30-day money back guarantee on the subscription and every product. Request a refund through Gumroad, no questions asked.
Every Tuesday: a production-ready detection rule, a real incident case study, a hunt hypothesis with a working query, and a career tip. Plus monthly Office Hours, private Discord, and a growing detection archive. Founding members lock in $14.99/month for life.
The blog gives you the query. The products give you the full operational picture: required log sources, false positive guidance, investigation steps, MITRE mapping, ticket wording, and the escalation path an analyst needs to close the alert properly.
Yes. Cancel anytime through Gumroad, no lock-in. Access to the Discord and detection archive lasts as long as your subscription is active. The one-time products are yours to keep permanently.
Everything on this site has been used in a real SOC environment. Buy once and keep it, or stay current every Tuesday. Either way you're getting tools that actually work at 2AM.
Severity matrix, 5-phase process, 8 critical Event IDs, Splunk cheatsheet. One page. Free forever.
Get the Free Checklist