
Writing Your First Sigma Rule
A practical walk-through of authoring a portable detection rule with Sigma, from logsource to test.
From suspicious bytes to actionable intelligence.

A practical walk-through of authoring a portable detection rule with Sigma, from logsource to test.

Hunting for east-west movement in Windows event logs, mapped to MITRE ATT&CK.

Walking a credential-phishing case from first report to containment and lessons learned.

Decoding and assessing an encoded PowerShell command during incident triage.

Gathering open-source intelligence responsibly, starting with what is already public.

Turning scattered observations into a structured CTI profile your defenders can act on.

Threat hunting doesn't require enterprise tools. You can simply start with what you already have.