Guides defensive security analysis—alert triage, log and SIEM investigation, threat hunting, detection
engineering basics, MITRE ATT&CK mapping, incident scoping, containment recommendations, and DFIR
evidence handling for SOC and blue-team analysts.
Use when investigating security alerts, writing detection rules, tuning false positives, analyzing
EDR/network/auth logs, building timelines of suspicious activity, recommending containment steps,
or documenting findings for incident command—not for enterprise security strategy (cybersecurity),
CI/CD pipeline hardening (devsecops), offensive pentest execution (authorize red team separately), or
LLM adversarial testing (ai-red…