Security operations
Detecting and responding to attacks: detection rules, SOC triage, phishing and email analysis, forensics, threat hunting, incident playbooks, vulnerability management and CTF practice.
Download all 23
- Analyse raw email headers
Analyses raw email headers for the delivery path, SPF, DKIM and DMARC results, alignment, spoofing signs and relay anomalies, explaining each finding in plain words for analysts and support staff.
- Analyse a packet capture summary
Analyses a packet capture summary from a tool's output to identify protocols, suspicious connections, beaconing and data transfer patterns, and suggests filters and checks to inspect next.
- Analyse a suspicious script for defenders
Explains what a suspicious script or obfuscated command does for defenders, deobfuscating step by step, extracting defanged indicators and rating risk, without improving or weaponising it.
- Build a forensic timeline
Builds a forensic timeline from parsed host and log artefacts, normalising time zones, correlating events, separating attacker actions from normal activity and listing evidence gaps.
- Coach a CTF challenge
Coaches a learner through an authorised capture-the-flag challenge with graded hints, asking what they have tried and teaching the underlying concept and its defence without handing over the flag.
- Detection engineer
Acts as a detection engineer who writes detections as code, tests them against real and synthetic data, tunes false positives and tracks coverage against attacker techniques.
- Investigate cloud audit logs
Investigates AWS, GCP or Azure audit logs for suspicious activity such as new access keys, privilege changes, unusual regions, logging tampering or data exports, and recommends containment steps.
- Investigate a reported phishing email
Investigates a phishing email reported by staff - extracts defanged indicators, reaches a verdict, scopes who received, clicked or replied, and lists blocking, reset and user communication steps.
- Map detection coverage to attack techniques
Maps an organisation's existing detections to attack techniques, finds coverage gaps for its threat profile and prioritises new detections by likelihood, impact and data availability.
- Plan a security tabletop exercise
Plans a security tabletop exercise with a realistic scenario, timed injects, roles, discussion questions, decision points, a facilitator guide and an after-action report template.
- Prioritise a vulnerability backlog
Prioritises a vulnerability scan backlog by severity, exploitation evidence, exposure and asset value, grouping fixes into patch waves with owners, deadlines and time-limited exceptions.
- Ransomware response track
Guides a team through a ransomware incident in gated steps - contain, preserve evidence, scope, choose a recovery path, restore safely, then communicate and learn - with decisions logged.
- Review firewall and security group rules
Reviews a firewall or cloud security group rule set for overly permissive, shadowed and unused rules, missing egress controls and documentation gaps, and plans a safe staged cleanup.
- SOC analyst
Acts as a seasoned security operations analyst who triages on evidence, documents everything, escalates early when impact is possible and stays calm under alert floods.
- Triage a SOC alert
Walks a SOC analyst through triaging a security alert turn by turn, asking for the enrichment that matters, weighing benign explanations, reaching an evidenced verdict and writing the escalation note.
- Write a bug bounty report
Writes a clear bug bounty or disclosure report for an in-scope finding, with summary, affected asset, reproduction steps, honest impact, evidence and remediation in the programme's format.
- Write an incident response playbook
Writes an incident response playbook for one scenario, such as business email compromise or a lost laptop, with triggers, roles, containment, evidence, communication, recovery and review steps.
- Write a security awareness module
Writes a short security awareness module for staff on one topic, such as phishing, MFA fatigue or safe file sharing, with realistic examples, clear actions, a quiz and a one-page reminder.
- Write a SIEM investigation query
Writes a SIEM or log query for an investigation question in the platform's query language, stating field assumptions, explaining each step, and adding performance tips and a way to validate results.
- Write a Sigma detection rule
Writes a Sigma detection rule from an attack behaviour or log samples, with log source, selection and filter logic, false-positive notes, ATT&CK tags and positive and negative test events.
- Write a threat hunting plan
Writes a hypothesis-driven threat hunting plan with data sources, queries to run, expected benign baselines, what a finding looks like and how to turn results into detections.
- Write a threat intelligence brief
Writes a threat intelligence brief from supplied reports, summarising the threat, its relevance to the organisation, defanged indicators, recommended actions and a stated confidence level.
- Write a YARA rule
Writes a YARA rule for a malware family or suspicious file pattern from defender-supplied indicators, balancing strings and conditions to limit false positives, with test and tuning guidance.
Not: building secure software, secure review and hardening (security); personal account safety (digital-safety); outages with no attacker (incident).