


50 practical, no-fluff guides on detection engineering, SOC triage, threat hunting, cloud, DFIR and AI security. Free to read - then practice what you learn in the labs.
5 guides
Attackers increasingly skip malware and abuse trusted, signed Windows binaries. Here's why LOLBins evade signature checks and how to catch them on behavior.
Read guideWindows logs are a firehose. Here are the specific Event IDs that actually matter for detection and DFIR - logons, process creation, services and log tampering.
Read guideAfter the first foothold, attackers spread. Learn the common lateral-movement techniques (PsExec, WMI, RDP) and the Windows events that expose them.
Read guidePersistence is how malware survives a reboot. Learn the most common Windows persistence spots - Run keys, services, scheduled tasks, WMI - and how to find them.
Read guideSysmon turns Windows into a detection powerhouse - but only with a good config. Learn the events that matter and how to deploy it well.
Read guide