Reference Material.
Not A Course.
Guides, cheatsheets, references, and playbooks for the moment you need one fact fast. H3AD-LEARN teaches a topic end to end; H3AD-REF just answers the question and gets out of your way. First up under Guides: writing YARA rules that hunt instead of just making noise.
YARA Rule WritingLIVE
Rule anatomy, string and condition syntax, and the habits that keep a rule from becoming noise.
Sigma Rule WritingLIVE
Detection block syntax, condition logic, correlation rules, and backend-conversion gotchas.
Regex For Log ParsingLIVE
Anchors, extraction patterns, greedy-vs-lazy quantifiers, and engine differences that break parsers.
Suricata & Snort Rule WritingLIVE
Header anatomy, sticky buffers vs deprecated modifiers, detection keywords, and the pitfalls that leave a rule blind.
Structured Analytic TechniquesLIVE
ACH, Key Assumptions Check, Devil's Advocacy, and Indicators of Change — bias-reduction methods for CTI calls.
Effective Detection LogicLIVE
False-positive reduction, ATT&CK mapping discipline, and testing before deploy — across YARA, Sigma, and Suricata alike.
Threat Hunting MethodologyLIVE
Hypothesis anatomy, where hunts come from, and the pitfalls that turn a hunt into confirmation bias.
Log Parsing & NormalizationLIVE
Syslog, CEF, LEEF, and ECS/JSON format differences, and the field-mapping gotchas that break correlation.
SPF, DKIM & DMARC SyntaxLIVE
Record anatomy, SPF mechanisms, and the DMARC alignment rules that actually stop spoofing.
Cloud Audit Log GuideLIVE
AWS CloudTrail, Azure Activity/AD, and GCP Cloud Audit Logs side by side, plus the data-plane logging gap most environments never close.
PowerShell For Incident ResponseLIVE
Core IR cmdlets, remote fleet-wide collection, and script block logging setup.
KQL / XQL / SPL SyntaxLIVE
The same query written in Sentinel/Defender KQL, Cortex XQL, and Splunk SPL, side by side.
Wireshark Display FiltersLIVE
Filter syntax basics plus scenario-grouped filters for spoofing, tunneling, beaconing, and cleartext creds.
tcpdump Command ReferenceLIVE
Basic syntax, BPF capture filters, common one-liners, and output flags.
Volatility3 CommandsLIVE
Plugin reference for process, network, injection, credential, filesystem, and command-history analysis.
Nmap Scan ReferenceLIVE
Scan types, host and port options, timing templates, NSE script categories, and output formats.
Windows Event ID CheatsheetLIVE
The ~28 highest-signal event IDs for fast triage, with a cross-link to WIN-EVT's full 105-event catalog.
Sysinternals & Windows CLI ForensicsLIVE
The Sysinternals suite plus native tasklist/wmic/reg/netstat/PowerShell commands for live triage.
Manual Host Triage (No EDR)LIVE
Investigating Windows and Linux hosts with zero security tooling — native commands only.
Protocol & Port ReferenceLIVE
Common ports and services with a SOC-relevance note on which ones signal lateral movement.
Packet Structure ReferenceLIVE
Ethernet, IP, TCP, and UDP header field layout, byte by byte.
Registry Key Quick ReferenceLIVE
Persistence, execution evidence, user activity, device history, and credential-relevant registry keys.
Attack Lifecycle & Adversary ModelsLIVE
Kill Chain, Courses of Action Matrix, Pyramid of Pain, Diamond Model, ATT&CK, and D3FEND — one diagram each.
Incident Response & Analysis ModelsLIVE
OODA Loop, NIST IR Lifecycle + PICERL, Order of Volatility, and Malware Analysis Methodology.
Defensive & Hunting Maturity ModelsLIVE
Sliding Scale of Cyber Security, SOC Visibility Triad, PEAK, and Hunting Maturity Model + TaHiTI.
Threat Intel CyclesLIVE
CTI Lifecycle and F3EAD — the strategic and tactical production cycles CTI runs on.
IOC vs IOALIVE
Indicator types, the IOC lifecycle, and why artifact-only detection ages out fast.
Admiralty Code & TLPLIVE
Source reliability (A-F), info credibility (1-6), and TLP 2.0's five sharing levels.
Threat Actor Naming Cross-ReferenceLIVE
Mandiant, CrowdStrike, Microsoft, and MITRE names for the same 15 well-tracked groups.
CTI Analyst ReferenceLIVE
ICD 203 words of estimative probability, plus STIX 2.1 object types and TAXII.
SOC Operations ReferenceLIVE
Tier 1/2/3 analyst responsibilities and escalation, plus the MTTD/MTTA/MTTR/dwell-time glossary.
Ransomware IRLIVE
Immediate triage, the IR lifecycle applied to ransomware, containment/eradication checklists, and escalation decision points.
Data Exfiltration AlertLIVE
Triage steps, true/false positive indicators, escalation criteria, and containment for an exfil alert.
Network Connection AlertLIVE
Triage for beaconing, C2, and unusual-connection alerts, from trigger to containment.
Malware / Execution AlertLIVE
Triage for an EDR/AV execution alert, from verdict source to containment and hash hunting.
Suspicious PowerShell AlertLIVE
Decoding encoded commands, spotting download cradles and AMSI bypasses, and containment.
BEC & Phishing ResponseLIVE
Triage for a reported phish or business email compromise, from header preservation to wire recall.
Authentication Anomaly AlertLIVE
Password spray, brute force, impossible travel, and non-business-country logins triaged as one pattern.
Privilege Escalation AlertLIVE
Group changes, token manipulation, and UAC bypass, from what escalated to what it was used for.
Command & Control (C2) AlertLIVE
Beacon detection, framework fingerprints, and telling a live implant from a chatty legitimate service.
Escalation Matrix & Severity ClassificationLIVE
Sev1-Sev4 definitions, response SLAs, and escalation paths every alert playbook points back to.
Shift Handover TemplateLIVE
Open incidents, watch items, and pending escalations — structured for 24/7 shift handoff.
Chain of Custody ChecklistLIVE
Documentation fields and collection sequence that keep digital evidence defensible.