Blog
Field notes for SOC analysts
Practical, no-fluff guides on IOC triage, investigating suspicious indicators, and choosing the right threat-intel source for the question in front of you.
- 5 min read
Why Threat Intelligence Belongs in Your Browser
SOC teams spend millions on SIEM, SOAR, and TI platforms — yet the analyst still tab-hops to answer a simple question about an IOC. Here is the case for putting threat intel where the work happens.
SOC toolinganalyst experiencethreat intelligence - 4 min read
Defanging and Refanging IOCs: A Practical Guide
Why IOCs get defanged, the common defang styles you will encounter, and how to refang safely before you pivot — without accidentally clicking a live malicious link.
IOC handlingdefangfundamentals - 7 min read
VirusTotal, AbuseIPDB, Shodan, GreyNoise & ipinfo: When to Use Each
Five threat-intelligence sources, five different jobs. A practical guide to what each one is actually good at, and how they combine into a complete picture of an IOC.
threat intelligencetoolssource selection - 5 min read
IOC Triage: A Repeatable Workflow for Busy SOC Analysts
Triage is about deciding fast what deserves deep investigation. Here is a lightweight, repeatable IOC triage workflow that scales across IPs, domains, URLs, and hashes.
IOC triageSOC workflowalert fatigue - 6 min read
How to Investigate a Suspicious IP Address: A SOC Analyst's Workflow
A repeatable, source-by-source workflow for triaging a suspicious IP address — reputation, noise, exposure, and geolocation — without drowning in browser tabs.
IOC triageIP investigationSOC workflow