Current focus
What I'm working on right now
TryHackMe Writeups (Sanitized)
Building
THM
Investigation
Writeups
Elastic Stack: Winlogbeat → Elasticsearch → Kibana
In progress
Elastic
Windows Logs
Pipeline
Categories
How I organize labs
Network
Net
Endpoint
EDR
SIEM / Detection
SIEM
Threat Hunting
Hunt
Recent writeups
Examples (add links as you publish)
Investigating with Splunk — notes
Add link
PCAP triage workflow
Planned
Linux auth log investigation
Planned
Suggest a lab
Ideas welcomeIf you have an authorized lab or a learning path you think I should run, send it to me. I'm especially interested in realistic SOC scenarios and detection validation.