SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

SOC//LIFE

Security analysis, explained.

Real-world attack behavior turned into investigations, detections, and threat hunts.

Detection Packs

Build environment-aware Splunk and Microsoft Sentinel detection packs from the SOC//LIFE detection library.
Open Detection Packs

Explore

Choose a path

Follow an investigation, see how its behavior can be detected, then search for the same activity elsewhere.

Recent work

Start with an analysis

Each entry connects the initial question to the evidence and conclusion.

About the analyst behind this work