Products Sample Issue Weekly Intel Pack FAQ Blog
Built from 10 years of real SOC operations

The detection tools that actually exist in production environments.

Detection queries, IR runbooks, and threat hunting playbooks built from real incidents at major Canadian financial institutions. Not adapted from vendor docs.

Used on real incidents · CrowdStrike · Splunk · Microsoft Sentinel

Want new detection rules every Tuesday? See the Weekly Intel Pack →
CISA KEV — Active Exploits
LIVE
Vulnerabilities confirmed exploited in the wild
Fetching latest threats...
The problem

Most SOC content is written by people who've never worked a real alert.

Vendor documentation is written to sell products. Certification courses are written to pass exams. Consultant blogs are written to generate leads. None of it is written by someone who worked a ransomware incident at a financial institution last Tuesday.

  • Generic queries that don't account for your actual log schema
  • Runbooks without false positive guidance or investigation steps
  • Threat hunting playbooks with no working queries attached
  • IR checklists that assume perfect data and unlimited time
What's different here
  • Every query has been run against real production data, not lab data
  • Every runbook includes the false positive guidance that took years to tune
  • Every playbook includes the working query behind the hypothesis
  • Every document includes the ticket wording an analyst needs at 2AM
One-time purchase · Own it forever

Start with the foundation

Production-tested SOC tools you buy once and keep forever. No subscription required.

SOC Starter Kit
$39
Best for junior to mid-level analysts who need a repeatable triage and investigation process.
One-time · PDF + DOCX · Instant download · 30-day money back

  • Alert Triage Handbook — severity matrix, 5-phase process, 10 most common mistakes
  • IR Runbook Set — step-by-step response for 4 common incident types
  • Threat Hunting Playbook — hypothesis framework with working queries
  • Quick Reference Card — critical Event IDs, Splunk cheatsheet, one page
  • CrowdStrike LogScale, Splunk SPL, and Sentinel KQL examples throughout
  • MITRE ATT&CK mappings on every detection technique
  • Ticket wording templates for escalation and communication
  • False positive guidance for every query included
View sample pages → Get SOC Starter Kit — $39
Instant download · 30-day money back, no questions asked
IR Runbook Bundle
$49
Built for analysts handling active incidents. Phishing, ransomware, credential compromise, insider threat.
One-time · PDF + DOCX · Instant download · 30-day money back

  • Phishing IR Runbook — detection to recovery, with communication templates
  • Ransomware IR Runbook — containment, evidence, patient zero investigation
  • Credential Compromise Runbook — session revocation, lateral movement tracing
  • Insider Threat Runbook — behavioral indicators, HR coordination, legal steps
  • Post-Incident Review Template — lessons learned, timeline reconstruction
  • Copy-pasteable detection queries for CrowdStrike, Splunk, and Sentinel
  • Escalation matrices with named roles and contact methods
  • Executive communication templates pre-written and approved
  • Legal and regulatory notification guidance for financial sector
  • Scripts for common automation steps included
View sample pages → Get IR Runbook Bundle — $49
Instant download · 30-day money back, no questions asked
Complete Bundle — Best Value
$79
Everything from both kits. 8 documents total. Save $9 vs buying separately.
One-time · PDF + DOCX · Instant download · 30-day money back

  • All 4 documents from the SOC Starter Kit
  • All 5 documents from the IR Runbook Bundle
  • CrowdStrike, Splunk, Sentinel, Entra ID, MITRE ATT&CK coverage
  • Every document in both PDF and editable DOCX format
  • Alert Triage Handbook
  • IR Runbook Set
  • Threat Hunting Playbook
  • Quick Reference Card
  • Phishing IR Runbook
  • Ransomware IR Runbook
  • Credential Compromise Runbook
  • Insider Threat Runbook
  • Post-Incident Review Template
View Starter Kit sample → Get Complete Bundle — $79
Instant download · 30-day money back, no questions asked
Not ready to buy yet? Download the free triage checklist first — no email required.
For analysts who want to stay current

A new production detection rule every Tuesday.

The one-time kits give you the foundation. The Intelligence Pack keeps you current — a new detection rule, a real incident case study, a hunt hypothesis, and a career tip, every single week.

Every issue is built from something that actually happened. A real alert that fired. A real investigation that ran. A real attacker technique that showed up in a production environment.

Plus monthly Office Hours where you can ask questions directly, and a private Discord with working analysts.

What ships every Tuesday
Detection Rule
Production-ready for CrowdStrike, Sentinel, or Splunk. Rotating weekly.
Case Study
A real incident walkthrough — what fired, what was investigated, what almost got missed.
Hunt Query
A hypothesis and working query to run proactively, not just react to alerts.
Career Tip
One concrete move for promotion, interviews, or handling friction with your team.
Founding Member Pricing
$29 $14.99 / month
Locked for life. Annual $149 — save 2 months.
  • Production detection rule every Tuesday
  • Real incident case study, not theory
  • Hunt hypothesis with working query
  • Monthly Office Hours — live Q&A, recording sent to all subscribers
  • Private Discord + growing detection archive
30-day money back · cancel anytime · founding member price locked for life
View a sample issue first →
See exactly what you get

A real example.
Not a description of value.

This is one production detection rule from the archive, complete and unedited. Every Tuesday subscribers get a new one like it — required logs, false positives, tuning notes, investigation steps, MITRE mapping, and ticket wording included.

Written by a working SOC and threat hunting analyst with 10+ years across CrowdStrike, Splunk, Sentinel, and Defender. Examples sanitized for education.

Detection rule — CrowdStrike LogScale
// PowerShell from Office or browser — Critical
#event_simpleName=ProcessRollup2
ImageFileName=/\/powershell\.exe$/i
ParentBaseFileName IN (
  "WINWORD.EXE", "OUTLOOK.EXE",
  "chrome.exe", "msedge.exe"
)
| table @timestamp ComputerName
    UserName CommandLine
| "sort" @timestamp desc

// Rarely legitimate in enterprise.
// Treat as high confidence, investigate immediately.
From early readers — unedited

What practitioners are saying

“

I downloaded the free SOC starter kit first just to see what kind of material this was. Honestly, it was better than I expected. The severity matrix and step-by-step triage flow are the kind of things I can actually use during a shift, not just read once and forget.

Mark Lee
Information Security Analyst II
Downloaded the free Starter Kit
“

The best part was how everything connected together — the detection rule, the hunt query, and the case study were all based on a real SOC-style scenario. It helped me think through what to check, what logs matter, how to reduce false positives, and how to write up the ticket.

David H.
Senior SOC Analyst
Subscriber, first Tuesday issue
“

I found the blog first and liked that the posts were not generic cybersecurity content. The hunting queries, investigation steps, and walkthroughs are written in a way that makes sense for someone actually working alerts.

Kashif K.
Senior Splunk Consultant
Reader of the blog and hunting guides
Who built this

Built by someone who still works alerts.

Senior cybersecurity analyst with 10+ years in SOC operations, incident response, and threat hunting at major Canadian financial institutions. Every query and runbook on this site has been used on a real incident in a production environment, not adapted from vendor documentation by a consultant who theorizes about security.

CISSP · CEH · SANS FOR508 · CrowdStrike · Splunk · Microsoft Sentinel · Defender

Read the full story →
10+Years in SOC and IR
4SIEM and EDR platforms
0Textbook theory
FAQ

Common questions

Subscription or one-time — which should I get?+

If you need something to use right now — triage process, runbooks, hunting playbook — start with one of the one-time kits. They're immediately usable and you keep them forever. If you want new detection rules and case studies every week plus Office Hours access, the Intelligence Pack is the right add-on. Many people use both.

What platforms are covered?+

CrowdStrike Falcon LogScale, Microsoft Sentinel KQL, and Splunk SPL. The one-time kits include examples across all three. The Intelligence Pack rotates weekly so over a month you get coverage across all three platforms.

Is there a money back guarantee?+

Yes. 30-day money back guarantee on the subscription and every product. Request a refund through Gumroad, no questions asked.

What's in the Weekly Intelligence Pack?+

Every Tuesday: a production-ready detection rule, a real incident case study, a hunt hypothesis with a working query, and a career tip. Plus monthly Office Hours, private Discord, and a growing detection archive. Founding members lock in $14.99/month for life.

Why pay if the blog already shows real queries?+

The blog gives you the query. The products give you the full operational picture: required log sources, false positive guidance, investigation steps, MITRE mapping, ticket wording, and the escalation path an analyst needs to close the alert properly.

Can I cancel the subscription anytime?+

Yes. Cancel anytime through Gumroad, no lock-in. Access to the Discord and detection archive lasts as long as your subscription is active. The one-time products are yours to keep permanently.

Production tools. Real incidents. Yours to keep.

Everything on this site has been used in a real SOC environment. Buy once and keep it, or stay current every Tuesday. Either way you're getting tools that actually work at 2AM.

Complete Bundle — $79 Free Checklist First
Before you go

Free SOC Triage Checklist

Severity matrix, 5-phase process, 8 critical Event IDs, Splunk cheatsheet. One page. Free forever.

Get the Free Checklist