CTI / threat intelligence — topics
Cyber threat intelligence and detection engineering. Focus on tradecraft attribution, collection management, and translating intel to detection.
Adversary tradecraft (named actor playbooks)
- apt-tradecraft-russian-svr-fsb — APT28/29 patterns
- apt-tradecraft-chinese-mss — APT10/40 patterns
- apt-tradecraft-dprk-lazarus — DPRK financial / espionage
- apt-tradecraft-iranian-irgc — APT33/34/35 patterns
- ransomware-affiliate-playbook — modern ransomware shape
Detection engineering
- detection-engineering-pyramid-of-pain — Bianco’s pyramid
- atomic-red-team-emulation-deep — testing detections
- siem-detection-use-case-catalog (cross-link)
Behavioral analytics / ML detection
SOC operations
- soc-shift-handoff-runbook
- soc-runbook-design
- soc-ticket-hygiene-mttr
- soc-tier-1-tier-2-tier-3-progression
- mssp-mdr-vendor-relationships
Threat hunting
Identity-centric defence
Coverage frameworks
Org-wide culture
CTI process
- cti-collection-management — feeding the SOC