Current focus
What I'm working on right now
Threat Intelligence Lab: MISP Containerization
Completed
Threat Intel
Docker
Ubuntu Core
DevSecOps
Elastic Stack: Winlogbeat → Elasticsearch → Kibana
In progress
Elastic
Windows Logs
Pipeline
Categories
How I organize labs
Network
Net
Endpoint
EDR
SIEM / Detection
SIEM
Threat Hunting
Hunt
Recent writeups
Examples (add links as you publish)
Investigating with Splunk — notes
Planned
Threat Intelligence Lab: MISP Containerization
Completed
Suggest a lab
Ideas welcomeIf you have an authorized lab or a learning path you think I should run, send it to me. I'm especially interested in realistic SOC scenarios and detection validation.