Home
SOC Playbooks
SOC Investigation Playbooks
A library of investigation playbooks in one standard format — alert summary, initial triage, numbered investigation steps, MITRE ATT&CK mapping, KQL queries, false-positive considerations, and a final verdict.
In development
This section is being built out. Here’s what it will hold:
- Suspicious PowerShell execution
- Phishing investigation
- Brute force & password spray
- Impossible travel / suspicious sign-in
- Privilege escalation
- Data exfiltration
- Ransomware investigation
- Malware detection
Built from real SOPs written against a live honeypot-to-Sentinel environment — the format already runs triage → investigation steps → MITRE → KQL → verdict.