Documentation.
Technical documentation, procedures and reference material covering infrastructure, SOC operations and cybersecurity.
SOC L1 overview
Monitoring, triage, escalation, a note. An alert is not an incident.
OPEN DOCUMENTATION →WAZUHWazuh basics
Agent, manager, indexer, dashboard. An alert is born from a log, not a wish.
OPEN DOCUMENTATION →LINUXLinux logs for SOC
journald, auth, syslog. Time, host, process, user — before an alert exists.
OPEN DOCUMENTATION →WINDOWSWindows logs for SOC
Security, System, PowerShell. The channel and audit policy must be on, or the Event ID sheet lies.
OPEN DOCUMENTATION →