Skip to main content

Security resources

Quick checklists for security investigations.

Browse practical reminders for alert triage, Windows logs, detection reviews, and AWS investigations. Use them alongside—not instead of—guided training.

Reference library

Start with repeatable defensive workflows.

Each reference is designed to prompt the next useful question during an investigation or detection review.

SOC

Alert triage checklist

A repeatable sequence for validating an alert, establishing scope, collecting evidence, and recording escalation decisions.

  • Validate signal and data quality
  • Identify affected users and assets
  • Build the event timeline
  • Decide disposition and next action
Explore SOC analyst training →
Windows

High-value event sources

A compact investigation map for authentication, process creation, services, scheduled tasks, and account activity.

  • 4624 / 4625 — logon activity
  • 4688 — process creation
  • 7045 — service installation
  • Sysmon 1 / 3 / 13 — process, network, registry
See Splunk and Windows log training →
Detection

Detection review checklist

Questions to answer before releasing or tuning behavioral detection logic.

  • Is the required telemetry present?
  • Does the logic match the stated behavior?
  • Are positive and boundary cases tested?
  • Are response steps documented?
Explore Detection Engineering →
Cloud

AWS investigation pivots

High-signal questions for CloudTrail, IAM, GuardDuty, and EC2 investigations.

  • Which principal performed the action?
  • How was the role or session obtained?
  • Which resources and regions were affected?
  • What access or persistence remains?
Explore Security Engineering L3 →
Go beyond the checklist

Learn how to interpret the evidence behind each step.

The flagship programs turn these reference points into guided investigations, detections, hunts, and reports.

Explore training