Skip to content
Home

SOC Playbooks

SOC Investigation Playbooks

A library of investigation playbooks in one standard format — alert summary, initial triage, numbered investigation steps, MITRE ATT&CK mapping, KQL queries, false-positive considerations, and a final verdict.

In development

This section is being built out. Here’s what it will hold:

  • Suspicious PowerShell execution
  • Phishing investigation
  • Brute force & password spray
  • Impossible travel / suspicious sign-in
  • Privilege escalation
  • Data exfiltration
  • Ransomware investigation
  • Malware detection

Built from real SOPs written against a live honeypot-to-Sentinel environment — the format already runs triage → investigation steps → MITRE → KQL → verdict.