Ops Room Notes

Detection tips, lab writeups, tool guides, and Blue Team insights from the field.

2024-12-15
How to Build a Home SOC Lab for Under $0

A complete guide to building a functional SOC lab using VirtualBox, Splunk Free, and open-source tools — all at zero cost.

SOCLab Setup
Read →
2024-12-08
Detecting Cobalt Strike Beacons with Splunk SPL

Step-by-step detection methodology using SPL queries to identify Cobalt Strike C2 traffic patterns in network logs.

DetectionSIEM
Read →
2024-11-28
20 Windows Event IDs Every SOC Analyst Must Know

A practical reference covering the most critical Windows Event IDs for threat detection and incident response workflows.

WindowsDFIR
Read →
2024-11-20
PowerShell Obfuscation: A Defender's Decoding Guide

How attackers obfuscate PowerShell and how defenders can decode, detect, and alert on obfuscated execution at scale.

PowerShellMalware
Read →
2024-11-12
Wireshark for SOC Analysts: 10 Essential Filters

The Wireshark display filters every SOC analyst should have memorised, with real examples from network investigations.

WiresharkNetwork
Read →
2024-11-05
Breaking Into SOC: A Realistic Roadmap for 2025

No fluff. An honest guide on skills, certs, and labs that actually help you land a Tier-1 SOC analyst role without a degree.

CareerBeginner
Read →
// STAY UPDATED

New lab or writeup every 2 weeks

Follow on GitHub or Twitter/X to get notified when new content drops.

GitHub Twitter / X