Knowledge Hub
The reference I wish I’d had.
Practical, evergreen notes on the work — how a SOC runs, reading a capture, hunting in KQL, writing detections that hold up, and securing the platform underneath. Written for myself, cleaned up so they’re useful to anyone on the same ground. Search runs across every article and its sections.
3 articles · press / to search
Networking & Packet Analysis
2 articlesThe wire-level knowledge an analyst leans on — ports, protocols, and reading a capture.
Ports & port numbers
What a port is in plain English, TCP vs UDP and port states, the three ranges, every port that matters with how it's abused, the attacker's port-by-port view across the kill chain, and what a SOC watches for.
Wireshark for the SOC
Reading capture files the way an analyst does — a step-by-step walkthrough from capture to written finding, the analysis loop, display filters by protocol, attack-pattern signatures, and exactly what still leaks in encrypted traffic.
Microsoft Sentinel
1 articleOperating and engineering Sentinel — from data connectors to automation.