Skip to main content

Blue Team

Defensive operations reference.

A working knowledge base for SOC, IR, and DFIR work — Splunk SPL queries, PowerShell investigations, forensic commands, and response playbooks. Grows as new notes are written up.

Reference

Knowledge base.

Loading knowledge base...