Articles hub
Article collection

SOC & Blue Team articles

SIEM alerts, log analysis, triage workflows, and blue-team investigation

Learn security monitoring, alert triage, log analysis, SIEM operations, threat hunting, detection engineering, and incident response workflows.

Collection snapshot

Published articles in this collection

Best for: SOC analysts, detection engineers, and security monitoring teams

Published articles

8

Example topics

3

Learning paths

How to use this collection

Read → apply → reference

Each article is written as a practical knowledge block you can use on the job, in labs, or during audits.

1

Learn the concept

Understand the threat, control, or workflow with clear explanations.

2

Follow the checklist

Apply steps, commands, or evidence collection in your environment.

3

Connect to practice

Jump to related labs, tutorials, and tools to reinforce skills.

Example topics in this collection

  • SIEM alerts
  • Wazuh
  • Splunk
  • ELK
  • Log analysis
  • Incident triage
  • Phishing investigation
  • Threat hunting

Catalog

Articles in soc & blue team

Practical guides, checklists, and explainers focused on this security domain.

Outcomes

What you'll learn

  • Triage alerts and investigate suspicious authentication and phishing activity
  • Analyze logs from SIEM, EDR, and identity systems with structured workflows
  • Document incidents with timelines, impact, and remediation steps
  • Prepare for SOC interviews and blue-team career progression