Reference material, maintained like software.
Versioned, reviewed, signed. Four hubs covering the disciplines of threat management — written to be readable on your first week and useful on your thousandth.
Know the Threat
THREAT INTELLIGENCE & ANALYSIS
Collection, structured analysis, STIX and ATT&CK mapping, actor profiling — intel products people actually read.
1 guide · reviewed Aug 25, 2026
Detect & Hunt
DETECTION ENGINEERING & HUNTING
Sigma/YARA/KQL rule writing, detection-as-code, hypothesis-driven hunting, ATT&CK coverage and tuning.
1 guide · reviewed Aug 25, 2026
Test & Validate
ADVERSARY SIMULATION & EXPOSURE
BAS, purple teaming, atomic testing, tabletops and the broader CTEM story — where "do we actually stop this?" gets answered.
1 guide · reviewed Aug 25, 2026
Respond & Improve
IR, DFIR & OPERATIONS
IR playbooks, forensics fundamentals, post-incident review — feeding lessons back into intel and detections.
1 guide · reviewed Aug 25, 2026