TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 10 · 7 min readStart Your SOC Journey with SOC Analyst Training 101In today’s digital landscape, cyber threats are evolving at an unprecedented pace. From ransomware attacks targeting critical infrastructure to sophisticated phishing campaigns and advanced persistent00
JJJaewook Junginwoogi.me·Jun 6 · 8 min readThreat Hunting MethodologyMost security tools are reactive. Alerts fire after a rule matches, and analysts triage. Threat hunting flips that: you assume something has already evaded the tools, and you go look for it. This post00
RBRegő Botond Ronyeczinzerohook.hashnode.dev·Jun 4 · 9 min readTop 10 DNS Security Tools for Proactive Threat Hunting (2026)Most DNS security advice is reactive. Something breaks, you investigate. But the teams that catch problems early aren't waiting for alerts from their SIEM — they're actively mapping their own attack s00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 3 · 5 min readWhat Are the Tools Used in a SOC Analyst Workflow?In the fast-paced world of cybersecurity, a SOC Analyst is often the first line of defense against cyber threats. They monitor systems 24/7, investigate alerts, and respond to incidents before they ca00
Vvaishvikkansarainloghunter.hashnode.dev·May 22 · 9 min readHow to Investigate a Phishing Attack Step by Step (SOC Perspective) Phishing is the number one attack vector used by cybercriminals worldwide. According to multiple threat intelligence reports, over 90% of data breaches begin with a phishing email. As a SOC Analyst, k00
ZOZeroTrust Opsinnavyacyber.hashnode.dev·Apr 30 · 10 min readMy First Hands-On Threat Hunting Workshop Experience with Intel 471: Hunting CVE-2023-46604 from Curiosity to ConfidenceWhen I first heard about Intel 471’s Intelligence-Driven Threat Hunting Workshop: Vulnerability Post-Exploitation Behaviors, I wasn’t actively searching for another certification or workshop. In fact,00
TATaji Abdullahintechnofiles.hashnode.dev·Apr 23 · 2 min readUnderstanding Threat Hunting InitiationWhen I first learned about Threat Hunting, the biggest question I had was, how is the hypothesis formed, how do you come to the point of forming a hypothesis that serves as the basis for the threat hu00
PPromiseinpromise-security.hashnode.dev·Apr 5 · 2 min readAnalysing a Simulated Web Breach with Splunk (Deloitte Forage Cyber Task)1. Getting the logs into Splunk The task provided a web_activity.log file with HTTP requests grouped by internal IP addresses. My first step was to bring this data into Splunk so I could query and vis00
SMShubham Mishrainsammy-secops.hashnode.dev·Apr 3 · 40 min readFrom Security Tool to Credential Stealer: The TeamPCP Trivy Supply Chain AttackTL;DR — Read This First On March 19, 2026 at approximately 17:43 UTC, threat actor group TeamPCP silently redirected trivy-action@0.34.2 — a real, trusted release already running in thousands of CI/CD11C
BOBrian Olsoninhurrikane.net·Mar 30 · 10 min readWhat's in a Name: DNS as a Detection GoldmineI love DNS. I know that's a weird thing to say, but I've been doing DFIR and detection engineering for close to two decades, and no single protocol has given me more signal per dollar invested than DN61J